THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-46380 (MEDIUM 6.7) — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forge

[NVD] CVE-2026-46380 (MEDIUM 6.7) — compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forge

lownvdPublished 2026-08-14

CVE-2026-46380 CVSS: 6.7 MEDIUM Published: 2026-08-14T17:18:14.710

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata en

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-46380