Back

HIGH

V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http

Published Jul 29, 2026

Description

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.http.get() normalizes the backslash and connects to the internal host, enabling access to internal network services that the allowlist was intended to block.

Affected products

Remediation

Red Hat statement

This is an Important server-side request forgery (SSRF) bypass vulnerability in the `v` language's `net.urllib` and `net.http` components. This flaw allows a remote attacker to circumvent host-based allowlists by exploiting a URL parser differential, enabling unauthorized access to internal network services. Applications utilizing these components for URL validation and fetching are at risk of exposing internal resources.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 29, 2026
Updated Jul 29, 2026
Reserved Jul 28, 2026
CISA Vulnrichment
Updated Jul 29, 2026
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity Important
Public date Jul 29, 2026
ENISA EUVD
Assigner VulnCheck
Published Jul 29, 2026
Updated Jul 29, 2026
Exploited since n/a
EUVD-2026-50446