Race Condition Vulnerability in Slab Safeurl Product
CVE-2026-77972
9CRITICAL
What is CVE-2026-77972?
A race condition issue in the Slab Safeurl library enables an attacker controlling DNS responses to bypass intended validation mechanisms. The situation arises when initial hostname resolutions can provide an approved address, but subsequent lookups can shift to a blocked address. This introduces critical points where an attacker can redirect requests to internal network destinations that were supposed to be blocked, exploiting the timing differences in DNS resolution. This vulnerability has implications for both external attackers and legitimate hostname configurations that may switch addresses frequently.
Affected Version(s)
safeurl 0.1.0
safeurl feabbd0a13f83028ab24b71710526e9da9841f70
References
CVSS V4
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonatan Männchen / EEF
Jonatan Männchen / EEF
