PT-2026-77157 · Codewhale · Codewhale
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodeWhale versions prior to 0.8.64
Description
A server-side request forgery (SSRF) bypass exists in the DNS pinning logic. The issue stems from a failure to prevent time-of-check-time-of-use (TOCTOU) attacks, where a race condition occurs between the time a security check is performed and the time the resource is actually used. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, enabling unauthorized requests to internal IP addresses and bypassing SSRF mitigations.
Recommendations
Update CodeWhale to version 0.8.64 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codewhale