CVE-2026-67201
Description
A flaw was found in V, specifically within its net.urllib and net.http components. This vulnerability allows a remote attacker to bypass host-based allowlists by exploiting a difference in how URLs are parsed. By crafting a malicious URL with a backslash, an attacker can trick the system into validating a trusted host while actually connecting to an internal network service. This enables unauthorized access to internal resources that should otherwise be protected.
Statement
This is an Important server-side request forgery (SSRF) bypass vulnerability in the v language's net.urllib and net.http components. This flaw allows a remote attacker to circumvent host-based allowlists by exploiting a URL parser differential, enabling unauthorized access to internal network services. Applications utilizing these components for URL validation and fetching are at risk of exposing internal resources.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Availability,Access Control,Non-Repudiation
Technical Impact: DoS: Crash, Exit, or Restart; Bypass Protection Mechanism; Hide Activities
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.