{"id":"CVE-2026-42175","aliases":["GHSA-vh75-fwv3-pqrh","PYSEC-2026-3050"],"url":"https://o3.security/vulnerability/CVE-2026-42175","summary":"requests-hardened: Server-Side Request Forgery (SSRF) in requests-hardened  RFC 6598","details":"requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security features. Prior to , the SSRF protection in requests-hardened fails to block IP addresses within the RFC 6598 Shared Address Space (100.64.0.0/10). An attacker who can supply arbitrary URLs to requests-hardened could exploit this gap to access internal services hosted within 100.64.0.0/10. This is for example relevant in environments such as AWS EKS where 100.64.0.0/10 is commonly used as the default pod CIDR. The impact is environment-dependent, deployments that utilize the affected CIDR range for internal networking are exposed to SSRF bypass, while others may not be affected. This vulnerability is fixed in .","published":"2026-05-12T17:52:09.138Z","modified":"2026-08-07T11:51:05.968784111Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"requests-hardened","fixedVersion":"1.2.1"}],"fix":{"url":"https://github.com/saleor/requests-hardened/commit/a266b3958bb142bca515b3c230fdea19fbda327c","label":"saleor/requests-hardened@a266b39"},"references":[{"type":"WEB","url":"https://github.com/saleor/requests-hardened/releases/tag/v1.2.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42175.json"},{"type":"ADVISORY","url":"https://github.com/saleor/requests-hardened/security/advisories/GHSA-vh75-fwv3-pqrh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42175"},{"type":"FIX","url":"https://github.com/saleor/requests-hardened/commit/a266b3958bb142bca515b3c230fdea19fbda327c"},{"type":"FIX","url":"https://github.com/saleor/requests-hardened/commit/b7403f88d3b3689e57435b75b51691a160aaeef5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:05.968784111Z"}}