Server-Side Request Forgery Vulnerability in Compliance-Trestle by OSCAL Compass
CVE-2026-46380
6.7MEDIUM
What is CVE-2026-46380?
The Compliance-Trestle platform, a toolkit for managing compliance as code, is susceptible to a Server-Side Request Forgery (SSRF) attack due to the HTTPSFetcher._do_fetch() method processing a user-controlled URL directly with requests.get() without sufficient validation. This flaw can enable attackers to target internal services or cloud metadata endpoints, potentially exposing sensitive information. The issue has been addressed in versions 3.12.2 and 4.0.3 of Compliance-Trestle.
Affected Version(s)
compliance-trestle >= 4.0.0, < 4.0.3 < 4.0.0, 4.0.3
compliance-trestle < 3.12.2 < 3.12.2
