{"id":"GHSA-xgch-x3mx-cm3c","summary":"safeurl is Missing IPv6 CIDR Ranges in Blocklist","details":"The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked:\n- `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215)\n- `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602)\n- `3fff::/20`: documentation prefix (RFC 9637)\n- `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780)\n\n### Impact\nIf exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges.\n\n### Workarounds\nDisable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library.\n\n### Resolution\nUpgrade to v0.2.4\n\n### Credits\nsafeurl thanks @tonghuaroot for reporting.","aliases":["CVE-2026-54452","GO-2026-5997"],"modified":"2026-07-21T19:19:10.724316633Z","published":"2026-07-15T21:58:03Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-15T21:58:03Z","nvd_published_at":null,"cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/doyensec/safeurl/security/advisories/GHSA-xgch-x3mx-cm3c"},{"type":"PACKAGE","url":"https://github.com/doyensec/safeurl"},{"type":"WEB","url":"https://github.com/doyensec/safeurl/releases/tag/v0.2.4"}],"affected":[{"package":{"name":"github.com/doyensec/safeurl","ecosystem":"Go","purl":"pkg:golang/github.com/doyensec/safeurl"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-xgch-x3mx-cm3c/GHSA-xgch-x3mx-cm3c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}