Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w76h-q7c6-jpjp | compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem |
Fri, 14 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oscal-compass
Oscal-compass compliance-trestle |
|
| Vendors & Products |
Oscal-compass
Oscal-compass compliance-trestle |
Fri, 14 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue. | |
| Title | compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-14T16:10:14.408Z
Reserved: 2026-05-13T19:53:47.921Z
Link: CVE-2026-46380
No data.
Status : Received
Published: 2026-08-14T17:18:14.710
Modified: 2026-08-14T17:18:14.710
Link: CVE-2026-46380
No data.
OpenCVE Enrichment
Updated: 2026-08-14T17:30:12Z
Github GHSA