CVE-2026-75856
9.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Summary
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hmbown | CodeWhale | 0.8.5 < 0.8.41 | affected |
| Hmbown | CodeWhale | 0.8.41 | unaffected |
| Hmbown | CodeWhale | 0.8.5 < 0.8.41 | affected |
| Hmbown | CodeWhale | 0.8.41 | unaffected |
| Hmbown | CodeWhale | 0.8.41 < 0.8.64 | affected |
| Hmbown | CodeWhale | 0.8.64 | unaffected |
| Hmbown | CodeWhale | 0.8.41 < 0.8.64 | affected |
| Hmbown | CodeWhale | 0.8.64 | unaffected |
Weaknesses
- CWE-918: Server-Side Request Forgery (SSRF)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-6v2g-fpxh-pmmh
- https://github.com/Hmbown/CodeWhale/commit/26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e
- https://www.vulncheck.com/advisories/codewhale-before-ssrf-bypass-via-dns-pinning-toctou
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.