Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations. | |
| Title | CodeWhale before 0.8.64 SSRF Bypass via DNS Pinning TOCTOU | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T15:21:55.627Z
Reserved: 2026-08-18T11:03:08.682Z
Link: CVE-2026-75856
No data.
Status : Received
Published: 2026-08-18T16:18:21.133
Modified: 2026-08-18T16:18:21.133
Link: CVE-2026-75856
No data.
OpenCVE Enrichment
No data.