CVE-2026-52776 | CVSS: N/A
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach loopback, link-local, cloud-metadata, and internal network endpoints it was designed to block. The blocklist does not canonicalize IPv4-mapped IPv6 literals such as [::ffff:169.254.169.254], which resolve to IPv6Address objects that never match the blocked IPv4 ranges, and it does not block the unspecified address 0.0.0.0, whic
参考链接:
• https://github.com/oscal-compass/compliance-trestle/commit/5335ff873a2a68eb7de43
• https://github.com/oscal-compass/compliance-trestle/commit/d107cd16efe8eb15d46be
• https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-h47
📌 数据来源: NVD 官方