Race Condition Vulnerability in Slab Safeurl Product
CVE-2026-77972

9CRITICAL

Key Information:

Vendor

Slab

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-77972?

A race condition issue in the Slab Safeurl library enables an attacker controlling DNS responses to bypass intended validation mechanisms. The situation arises when initial hostname resolutions can provide an approved address, but subsequent lookups can shift to a blocked address. This introduces critical points where an attacker can redirect requests to internal network destinations that were supposed to be blocked, exploiting the timing differences in DNS resolution. This vulnerability has implications for both external attackers and legitimate hostname configurations that may switch addresses frequently.

Affected Version(s)

safeurl 0.1.0

safeurl feabbd0a13f83028ab24b71710526e9da9841f70

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Jonatan Männchen / EEF
.