Redirect-based SSRF leading to internal network access in curl_cffi (with TLS impersonation bypass)
Published Apr 6, 2026
8.6
HIGHCVSS 3.1
EPSS 0.45%
Description
curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpoints. In addition, curl_cffi’s TLS impersonation feature can make these requests appear as legitimate browser traffic, which may bypass certain network controls. This vulnerability is fixed in 0.15.0.
Affected products
-
Affected
- < 0.15.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Lexiforest | Curl Cffi | unknown | Affected
|
- < 0.15.0
- 0.15.0
- 0.15.0
- 0.15.0
- 0.15.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19293 Advisory
- https://github.com/advisories/GHSA-qw2m-4pqf-rmpp Advisory
- https://github.com/lexiforest/curl_cffi/security/advisories/GHSA-qw2m-4pqf-rmpp exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33752
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19293 | Advisory | |
| https://github.com/advisories/GHSA-qw2m-4pqf-rmpp | Advisory | |
| https://github.com/lexiforest/curl_cffi/security/advisories/GHSA-qw2m-4pqf-rmpp | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-33752 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub