CVE-2026-52776: CWE-184: Incomplete List of Disallowed Inputs in oscal-compass compliance-trestle
Compliance-trestle versions before 3.12.4 and versions 4.0.0 through 4.0.3 contain a vulnerability in the URLSecurityValidator that allows bypassing its blocklist for certain internal and cloud metadata IP addresses. This flaw enables attackers to cause the software to fetch data from restricted internal network endpoints, including loopback and cloud instance-metadata services. The issue arises because the validator does not properly canonicalize IPv4-mapped IPv6 literals and does not block the unspecified address 0.0.0.0. The vulnerability is fixed in versions 3.12.4 and 4.1.0.
AI Analysis
Technical Summary
Compliance-trestle's URLSecurityValidator is designed to prevent server-side request forgery by blocking access to loopback, link-local, cloud-metadata, and internal network endpoints. However, in affected versions (<3.12.4 and >=4.0.0 <4.1.0), the blocklist is incomplete: it fails to canonicalize IPv4-mapped IPv6 literals (e.g., [::ffff:169.254.169.254]) which resolve to IPv6Address objects not matched by the IPv4 block ranges, and it does not block the unspecified IPv4 address 0.0.0.0. This allows an attacker who can influence OSCAL artifacts fetched by trestle to bypass protections and cause HTTPSFetcher and SFTPFetcher to contact restricted internal services. The vulnerability is addressed in versions 3.12.4 and 4.1.0.
Potential Impact
An attacker able to supply or influence OSCAL artifacts fetched by compliance-trestle can bypass URL validation controls to make the software access internal network endpoints, including loopback interfaces, link-local addresses, cloud instance-metadata services, and unspecified addresses. This could lead to unauthorized internal network interactions, potentially exposing sensitive internal resources or metadata. The CVSS 4.0 score is 8.6 (high severity), indicating significant impact with network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality and integrity.
Mitigation Recommendations
Upgrade compliance-trestle to version 3.12.4 or later, or 4.1.0 or later, where this vulnerability is fixed. No other mitigation is required as the issue is resolved in these versions.
CVE-2026-52776: CWE-184: Incomplete List of Disallowed Inputs in oscal-compass compliance-trestle
Description
Compliance-trestle versions before 3.12.4 and versions 4.0.0 through 4.0.3 contain a vulnerability in the URLSecurityValidator that allows bypassing its blocklist for certain internal and cloud metadata IP addresses. This flaw enables attackers to cause the software to fetch data from restricted internal network endpoints, including loopback and cloud instance-metadata services. The issue arises because the validator does not properly canonicalize IPv4-mapped IPv6 literals and does not block the unspecified address 0.0.0.0. The vulnerability is fixed in versions 3.12.4 and 4.1.0.
CVSS v4.0
Score 8.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Compliance-trestle's URLSecurityValidator is designed to prevent server-side request forgery by blocking access to loopback, link-local, cloud-metadata, and internal network endpoints. However, in affected versions (<3.12.4 and >=4.0.0 <4.1.0), the blocklist is incomplete: it fails to canonicalize IPv4-mapped IPv6 literals (e.g., [::ffff:169.254.169.254]) which resolve to IPv6Address objects not matched by the IPv4 block ranges, and it does not block the unspecified IPv4 address 0.0.0.0. This allows an attacker who can influence OSCAL artifacts fetched by trestle to bypass protections and cause HTTPSFetcher and SFTPFetcher to contact restricted internal services. The vulnerability is addressed in versions 3.12.4 and 4.1.0.
Potential Impact
An attacker able to supply or influence OSCAL artifacts fetched by compliance-trestle can bypass URL validation controls to make the software access internal network endpoints, including loopback interfaces, link-local addresses, cloud instance-metadata services, and unspecified addresses. This could lead to unauthorized internal network interactions, potentially exposing sensitive internal resources or metadata. The CVSS 4.0 score is 8.6 (high severity), indicating significant impact with network attack vector, low complexity, no privileges or user interaction required, and high impact on confidentiality and integrity.
Mitigation Recommendations
Upgrade compliance-trestle to version 3.12.4 or later, or 4.1.0 or later, where this vulnerability is fixed. No other mitigation is required as the issue is resolved in these versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h47f-gmjp-m7rr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-52776"]
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a7c9b2bbf8831d539cdb508
Added to database: 08/12/2026, 16:11:23 UTC
Last enriched: 09/12/2026, 05:48:49 UTC
Last updated: 09/25/2026, 01:47:43 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.