CVE-2026-42175: Incomplete Is Private Ssrf Check

Relying solely on `ipaddress.is_private` for SSRF protection is insufficient. The `is_private` property does not block all non-publicly routable IP ranges, such as the RFC 6598 Shared Address Space (100.64.0.0/10) or multicast addresses. An attacker could exploit this to bypass SSRF filters and access internal services. Augment `is_private` with checks for m

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-42175-incomplete-is-private-ssrf-check --engine opengrep

Description

Relying solely on `ipaddress.is_private` for SSRF protection is insufficient. The `is_private` property does not block all non-publicly routable IP ranges, such as the RFC 6598 Shared Address Space (100.64.0.0/10) or multicast addresses. An attacker could exploit this to bypass SSRF filters and access internal services. Augment `is_private` with checks for m