PT-2026-37250 · Pypi · Requests-Hardened

CVE-2026-42175

·

Published

2026-05-05

·

Updated

2026-07-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions requests-hardened versions prior to 1.2.1
Description The Server-Side Request Forgery (SSRF) protection fails to block IP addresses within the RFC 6598 Shared Address Space (100.64.0.0/10). An attacker capable of supplying arbitrary URLs can exploit this gap to access internal services hosted within that range. This is particularly relevant in environments like AWS EKS, where 100.64.0.0/10 is commonly used as the default pod CIDR. The impact depends on the environment; deployments using this CIDR range for internal networking are exposed to SSRF bypass.
Recommendations Update to version 1.2.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42175
GHSA-VH75-FWV3-PQRH
PYSEC-2026-3050

Affected Products

Requests-Hardened