THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h47f-gmjp-m7rr (high) — compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

[GHSA] GHSA-h47f-gmjp-m7rr (high) — compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

highgithub_advisoriesPublished 2026-08-12

GHSA-h47f-gmjp-m7rr Severity: high CVE: CVE-2026-52776

compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0

### Summary

`compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h47f-gmjp-m7rr