#391 MEDIUM: SSRF bypass via DNS rebinding (TOCTOU)

closed medium Created 2025-12-11 22:21 · Updated 2025-12-16 20:45

Description

Edit
http_request.py:107-124 - DNS resolved at validation time, but request may resolve to different IP (DNS rebinding). TOCTOU vulnerability. Fix: Resolve DNS yourself and connect to IP directly, or use requests adapter to enforce IP at connection time.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...