Threat Advisory

Dssrf SSRF Bypass Allows Internal IPs to Connect

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting dssrf versions <= 1.0.3, CVE-2026-54722 with a CVSS score of 8.7, exists in the dssrf library due to an SSRF bypass flaw type. The attack vector is network-based and allows internal IPs to be unchecked by removing the `@` symbol from the raw URL string before parsing. This enables attacks via environment template management API. The business impact includes bypassing all internal IPv4 ranges, IPv6 addresses, AWS IMDS, and any internal hostname via userinfo prefix.

RECOMMENDATION:

We recommend you to update dssrf to version 1.0.4.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability affecting dssrf versions <= 1.0.3, CVE-2026-54722 with a CVSS score of 8.7, exists in the dssrf library due to an SSRF bypass flaw type. The attack vector is network-based and allows internal IPs to be unchecked by removing the `@` symbol from the raw URL string before parsing. This enables attacks via environment template management API. The business impact includes bypassing all internal IPv4 ranges, IPv6 addresses, AWS IMDS, and any internal hostname via userinfo prefix.

RECOMMENDATION:

We recommend you to update dssrf to version 1.0.4.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu