{"id":"CVE-2020-36474","aliases":["GHSA-x2xg-6wcj-6xf9"],"url":"https://o3.security/vulnerability/CVE-2020-36474","summary":"SafeCurl before 0.9.2 has a DNS rebinding vulnerability.","details":"SafeCurl before 0.9.2 has a DNS rebinding vulnerability.","published":"2021-08-20T15:15:06.837Z","modified":"2026-07-09T06:34:48.513903Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"vanilla/safecurl","fixedVersion":"0.9.2"}],"fix":{"url":"https://github.com/vanilla/safecurl/pull/2","label":"vanilla/safecurl#2"},"references":[{"type":"ADVISORY","url":"https://github.com/vanilla/safecurl/releases/tag/v0.9.2"},{"type":"FIX","url":"https://github.com/vanilla/safecurl/pull/2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:34:48.513903Z"}}