What is CVE-2026-67201?
CVE-2026-67201 is an SSRF bypass vulnerability in the V library up to version 0.5.2 that exploits a parser differential between net.urllib and net.http. Attackers can circumvent host-based allowlists by crafting URLs with a backslash in the authority. The fix is available in commit 85859f0.
Azərbaycanca: CVE-2026-67201, V kitabxanasının 0.5.2-yə qədər versiyalarında server-side request forgery (SSRF) bypass zəifliyidir. Bu, təcavüzkarlara net.urllib və net.http arasındakı parser fərqindən istifadə edərək host-based allowlist-ləri keçməyə imkan verir. Problemi aradan qaldırmaq üçün commit 85859f0 ilə təmin edilmiş düzəliş tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
How is CVE-2026-67201 exploited in the V library?
The vulnerability allows attackers to bypass host-based allowlists by exploiting a parser differential between net.urllib and net.http, enabling them to craft URLs with a backslash in the authority.
What measure should be taken to fix CVE-2026-67201?
The fix provided in commit 85859f0 must be applied to resolve the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.