{"id":"GHSA-373w-rj84-pv6x","aliases":[],"url":"https://o3.security/vulnerability/GHSA-373w-rj84-pv6x","summary":"SafeURL-Python's hostname blocklist does not block FQDNs","details":"### Description\nIf a hostname was blacklisted, it was possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding `.` to the end).\n\n### Impact\nThe main purpose of this library is to block requests to internal/private IPs and these cannot be bypassed using this finding. But if a library user had specifically set certain hostnames as blocked, then an attacker would be able to circumvent that block to cause SSRFs to request those hostnames.\n\n### Patches\nFixed by https://github.com/IncludeSecurity/safeurl-python/pull/6\n\n### Credit\nhttps://github.com/Sim4n6\n","published":"2023-06-29T15:02:16Z","modified":"2025-02-14T05:29:26.997226Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"safeurl-python","fixedVersion":"1.3"}],"fix":{"url":"https://github.com/IncludeSecurity/safeurl-python/pull/6","label":"IncludeSecurity/safeurl-python#6"},"references":[{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/security/advisories/GHSA-373w-rj84-pv6x"},{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/pull/6"},{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/commit/c4f9677f8790a58eaa1953bac286cca75a5f580e"},{"type":"PACKAGE","url":"https://github.com/IncludeSecurity/safeurl-python"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-14T05:29:26.997226Z"}}