CVE-2026-67201

Description

A flaw was found in V, specifically within its net.urllib and net.http components. This vulnerability allows a remote attacker to bypass host-based allowlists by exploiting a difference in how URLs are parsed. By crafting a malicious URL with a backslash, an attacker can trick the system into validating a trusted host while actually connecting to an internal network service. This enables unauthorized access to internal resources that should otherwise be protected.

Statement

This is an Important server-side request forgery (SSRF) bypass vulnerability in the v language's net.urllib and net.http components. This flaw allows a remote attacker to circumvent host-based allowlists by exploiting a URL parser differential, enabling unauthorized access to internal network services. Applications utilizing these components for URL validation and fetching are at risk of exposing internal resources.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Availability,Access Control,Non-Repudiation

Technical Impact: DoS: Crash, Exit, or Restart; Bypass Protection Mechanism; Hide Activities

Frequently Asked Questions

Want to get errata notifications? Sign up here.