Server-Side Request Forgery Vulnerability in Compliance-Trestle by OSCAL Compass
CVE-2026-46380

6.7MEDIUM

Key Information:

Vendor
CVE Published:
14 August 2026

What is CVE-2026-46380?

The Compliance-Trestle platform, a toolkit for managing compliance as code, is susceptible to a Server-Side Request Forgery (SSRF) attack due to the HTTPSFetcher._do_fetch() method processing a user-controlled URL directly with requests.get() without sufficient validation. This flaw can enable attackers to target internal services or cloud metadata endpoints, potentially exposing sensitive information. The issue has been addressed in versions 3.12.2 and 4.0.3 of Compliance-Trestle.

Affected Version(s)

compliance-trestle >= 4.0.0, < 4.0.3 < 4.0.0, 4.0.3

compliance-trestle < 3.12.2 < 3.12.2

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.