CVE-2026-27189: App Ingest Py Cwe 000 Cve 2026 27189

An HTTP client is explicitly configured to follow HTTP redirects automatically. If initial URLs are validated against SSRF but redirect URLs are not, an attacker could return a redirect pointing to an internal service, bypassing the SSRF filter. Set `follow_redirects=False` (or `allow_redirects=False`) and validate redirect targets manually against the SSRF

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-27189-app-ingest-py-cwe-000-cve-2026-27189 --engine opengrep

Description

An HTTP client is explicitly configured to follow HTTP redirects automatically. If initial URLs are validated against SSRF but redirect URLs are not, an attacker could return a redirect pointing to an internal service, bypassing the SSRF filter. Set `follow_redirects=False` (or `allow_redirects=False`) and validate redirect targets manually against the SSRF