[CVE-2026-52776] Compliance-trestle (Trestle) is a tooling platform for manag

CVE-2026-52776 | CVSS: N/A

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach loopback, link-local, cloud-metadata, and internal network endpoints it was designed to block. The blocklist does not canonicalize IPv4-mapped IPv6 literals such as [::ffff:169.254.169.254], which resolve to IPv6Address objects that never match the blocked IPv4 ranges, and it does not block the unspecified address 0.0.0.0, whic

参考链接:
https://github.com/oscal-compass/compliance-trestle/commit/5335ff873a2a68eb7de43
https://github.com/oscal-compass/compliance-trestle/commit/d107cd16efe8eb15d46be
https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-h47

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部