What is CVE-2026-46380?
CVE-2026-46380 is a Server-Side Request Forgery (SSRF) vulnerability in compliance-trestle, where the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows attackers to target internal resources. Users should upgrade to versions 3.12.2 or 4.0.3 immediately.
Azərbaycanca: CVE-2026-46380 compliance-trestle platformunda aşkarlanmış Server-Side Request Forgery (SSRF) zəifliyidir. Bu zəiflik HTTPSFetcher._do_fetch() metodunda istifadəçi tərəfindən təqdim edilən URL-in yoxlanılmadan birbaşa requests.get() funksiyasına ötürülməsi səbəbindən yaranır. Təsirə məruz qalan istifadəçilər dərhal 3.12.2 və ya 4.0.3 versiyalarına yeniləmə aparmalıdırlar.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
In which method of the compliance-trestle platform was CVE-2026-46380 discovered?
The vulnerability was discovered in the HTTPSFetcher._do_fetch() method.
Which versions should users upgrade to in order to mitigate this SSRF vulnerability?
Users should immediately upgrade to versions 3.12.2 or 4.0.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.