THREAT OPS › Threat News › [GHSA] GHSA-6v2g-fpxh-pmmh (critical) — CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
[GHSA] GHSA-6v2g-fpxh-pmmh (critical) — CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
GHSA-6v2g-fpxh-pmmh Severity: critical CVE: CVE-2026-75856
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
### Maintainer resolution
The CodeWhale maintainers validated this report. The affected package ranges are recorded in the advisory metadata. Version 0.8.64 contains the fix in commit 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e. Users should upgrade to 0.8.64 or later. The ori
MITRE ATT&CK techniques
Indicators of compromise
- 26de44a8bd5051f8f944ea60b2c37ae1d2b7d25esha1
- 8dff2f7525ead210a01347b48f53ae3f20d094ecsha1
- CVE-2026-75856cve
- http://mydomain.comurl
- 8.8.8.8ipv4
- 10.0.1.0/24cidr
- ads.tracker.iodomain
- ghcr.iodomain
Original source: https://github.com/advisories/GHSA-6v2g-fpxh-pmmh