V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
Published Jul 29, 2026
7.7
HIGHCVSS 4.0
EPSS 0.53%
Description
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a parser differential between net.urllib and net.http. Attackers can craft a URL containing a backslash in the authority section such that net.urllib.parse() extracts the trusted host for allowlist validation while net.http.get() normalizes the backslash and connects to the internal host, enabling access to internal network services that the allowlist was intended to block.
Affected products
-
- Version 0StatusaffectedConstraints<=0.5.2
- Version
-
- Version StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This is an Important server-side request forgery (SSRF) bypass vulnerability in the `v` language's `net.urllib` and `net.http` components. This flaw allows a remote attacker to circumvent host-based allowlists by exploiting a URL parser differential, enabling unauthorized access to internal network services. Applications utilizing these components for URL validation and fetching are at risk of exposing internal resources.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-67201 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2508519 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50446 Advisory
- https://github.com/vlang/v/commit/85859f0f3498d4091b38009c45ed390a97eeedc2 patch
- https://github.com/vlang/v/issues/27945 technical-descriptionexploit
- https://github.com/vlang/v/pull/27947 issue-tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-67201
- https://www.cve.org/CVERecord?id=CVE-2026-67201
- https://www.vulncheck.com/advisories/v-ssrf-bypass-via-parser-differential-in-net-urllib-and-net-http third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-67201 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2508519 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50446 | Advisory | |
| https://github.com/vlang/v/commit/85859f0f3498d4091b38009c45ed390a97eeedc2 | patch | |
| https://github.com/vlang/v/issues/27945 | technical-descriptionexploit | |
| https://github.com/vlang/v/pull/27947 | issue-tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-67201 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-67201 | ||
| https://www.vulncheck.com/advisories/v-ssrf-bypass-via-parser-differential-in-net-urllib-and-net-http | third-party-advisory |
Change history (0)
No recorded changes yet.