Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-77866: Slab safeurl may let attackers reach internal systems
CVE-2026-77866 · published 25 days ago
Summary
The safeurl component used in Slab can be tricked into contacting internal network addresses when an attacker supplies a specially crafted URL. Because only IPv4 addresses are checked against the block list, IPv6 or unresolved hostnames can bypass the protection and reach private servers. Update safeurl to the latest version or apply the vendor's recommended configuration change to ensure all address types are properly filtered.
What to do
- Update slab safeurl to version * or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | slab | safeurl | < * |
| Hex | slab | safeurl | >= 0.1.0 |
Original advisory text
SSRF protection bypass in safeurl via IPv6 addresses and unresolvable hosts
Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block.
Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected.
This issue affects safeurl: from 0.1.0 onward.
Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other address is treated as matching nothing, so a destination that is rejected in its IPv4 form is accepted when written as an IPv6 address, IPv6 entries in the blocklist never match, and a host that resolves to no IPv4 address is accepted regardless of where it points. Deployments that rely on the allowlist instead are unaffected, because there an unmatched address is rejected.
This issue affects safeurl: from 0.1.0 onward.
References
- https://github.com/slab/safeurl-elixir Product
- https://cna.erlef.org/cves/CVE-2026-77866.html
- https://github.com/slab/safeurl-elixir/commit/feabbd0a13f83028ab24b71710526e9da9...
- https://osv.dev/vulnerability/EEF-CVE-2026-77866
- https://hex.pm/packages/safeurl Product
- https://github.com URL
- https://repo.hex.pm URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77866... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-77866 Vendor Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Type
CWE-636Not Failing Securely ('Failing Open')
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta