CVE-2026-75856: CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
DNS-pinning failure allows natural failure of code, however with a custom DNS server that fails the initial requests and allows the secondary requests, it’s possible to bypass the logic.
References
- github.com/Hmbown/CodeWhale/commit/26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e
- github.com/Hmbown/CodeWhale/security/advisories/GHSA-6v2g-fpxh-pmmh
- github.com/advisories/GHSA-6v2g-fpxh-pmmh
- nvd.nist.gov/vuln/detail/CVE-2026-75856
- www.vulncheck.com/advisories/codewhale-before-ssrf-bypass-via-dns-pinning-toctou
Code Behaviors & Features
Detect and mitigate CVE-2026-75856 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →