Packages

SSRF Protection in Elixir 🛡️

Security advisory: This version has known vulnerabilities. View advisories

Current section

2 Advisories

Jump to
EEF-CVE-2026-77866 CVE-2026-77866

SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts

September 15, 2026
CVSS
?
9.0 / 10.0 Critical
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Affected Versions

>= 0.1.0
EEF-CVE-2026-77972 CVE-2026-77972

safeurl validated address is not bound to the request, allowing DNS rebinding

September 15, 2026
CVSS
?
9.0 / 10.0 Critical
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Affected Versions

>= 0.1.0

Checksum

Dependency Config

mix.exs

rebar.config

Gleam

erlang.mk

Package Details

Downloads Last 30 days, all versions
0 200 400 600 800

this version

74 491

yesterday

34

last 7 days

263

all time

106 701

Last Updated

Jan 15, 2025

License

BSD-3-Clause

Build Tools

mix

Publisher

slab slab

Owners