PT-2026-65615 · Pypi · Datamodel-Code-Generator

CVE-2026-55391

·

Published

2026-07-28

·

Updated

2026-08-18

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions datamodel-code-generator versions prior to 0.63.0
Description A server-side request forgery (SSRF) exists due to a time-of-check/time-of-use (TOCTOU) gap during DNS resolution. The software validates the resolved IP of a fetch target to block private or link-local addresses, but it does not pin this result. Consequently, the httpx library performs a second, independent DNS resolution to establish the connection. An attacker can use DNS rebinding—where a hostname resolves to a public IP during validation and a private IP during connection—to bypass the allow private network=False guard. This allows access to internal services, loopback addresses, and cloud-metadata endpoints such as 169.254.169.254. The issue is reachable when the tool fetches an attacker-influenced URL via the --url parameter or a remote $ref in a schema. The vulnerability involves the get body(), validate url for fetch(), and get ips from host() functions within the src/datamodel code generator/http.py file.
Recommendations Update datamodel-code-generator to version 0.63.0 or later.

Exploit

Fix

Time Of Check To Time Of Use

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55391
GHSA-VX7X-VCC2-C44G
OPENSUSE-SU-2026:11538-1
PYSEC-2026-3565

Affected Products

Datamodel-Code-Generator