Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/doyensec/safeurl
  4. ›
  5. CVE-2026-54452

CVE-2026-54452: safeurl is Missing IPv6 CIDR Ranges in Blocklist

July 15, 2026

The privateNetworks blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked:

  • 64:ff9b:1::/48: NAT64 local-use prefix (RFC 8215)
  • 5f00::/16: Segment Routing (SRv6) SIDs (RFC 9602)
  • 3fff::/20: documentation prefix (RFC 9637)
  • 100:0:0:1::/64: Dummy IPv6 Prefix (RFC 9780)

References

  • github.com/advisories/GHSA-xgch-x3mx-cm3c
  • github.com/doyensec/safeurl/releases/tag/v0.2.4
  • github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c
  • nvd.nist.gov/vuln/detail/CVE-2026-54452

Code Behaviors & Features

Detect and mitigate CVE-2026-54452 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.2.4

Fixed versions

  • 0.2.4

Solution

Upgrade to version 0.2.4 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/doyensec/safeurl/CVE-2026-54452.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:56 +0000.