{"id":"GHSA-373w-rj84-pv6x","summary":"SafeURL-Python's hostname blocklist does not block FQDNs","details":"### Description\nIf a hostname was blacklisted, it was possible to bypass the blacklist by requesting the FQDN of the host (e.g. adding `.` to the end).\n\n### Impact\nThe main purpose of this library is to block requests to internal/private IPs and these cannot be bypassed using this finding. But if a library user had specifically set certain hostnames as blocked, then an attacker would be able to circumvent that block to cause SSRFs to request those hostnames.\n\n### Patches\nFixed by https://github.com/IncludeSecurity/safeurl-python/pull/6\n\n### Credit\nhttps://github.com/Sim4n6\n","modified":"2025-02-14T05:29:26.997226Z","published":"2023-06-29T15:02:16Z","database_specific":{"cwe_ids":[],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-06-29T15:02:16Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/security/advisories/GHSA-373w-rj84-pv6x"},{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/pull/6"},{"type":"WEB","url":"https://github.com/IncludeSecurity/safeurl-python/commit/c4f9677f8790a58eaa1953bac286cca75a5f580e"},{"type":"PACKAGE","url":"https://github.com/IncludeSecurity/safeurl-python"}],"affected":[{"package":{"name":"safeurl-python","ecosystem":"PyPI","purl":"pkg:pypi/safeurl-python"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3"}]}],"versions":["1.0","1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-373w-rj84-pv6x/GHSA-373w-rj84-pv6x.json"}}],"schema_version":"1.9.0"}