CVE-2026-75856
Last modified
CVE-2026-75856 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Hmbown | CodeWhale | >= 0.8.5, < 0.8.41 |
| Hmbown | CodeWhale | >= 0.8.41, < 0.8.64 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-75856?
How severe is CVE-2026-75856?
How do I fix CVE-2026-75856?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-75850ArcadeDB before 26.8.1 fails to bind the authenticated princ…4.2
- CVE-2026-75851ArcadeDB server (com.arcadedb:arcadedb-server) in versions 2…9.9
- CVE-2026-75852ArcadeDB versions before 26.8.1 fail to enforce SASL authent…9.8
- CVE-2026-75853ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcade…8.8
- CVE-2026-75854ArcadeDB versions before 26.8.1 contain a missing authentica…9.8
- CVE-2026-75855ArcadeDB versions before 26.8.1 fail to sanitize database na…8.7
- CVE-2026-75857CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerab…7
- CVE-2026-75858CodeWhale (packages codewhale / codewhale-tui) versions >= 0…7.8
- CVE-2026-75859CodeWhale versions before 0.8.64 fail to validate file paths…7.5
- CVE-2026-7586A weakness has been identified in Open5GS up to 2.7.7. Affec…4.3
- CVE-2026-75860The JSON Options WordPress plugin through 0.0.4 does not hav…9.8
- CVE-2026-75861The Ultimate Gift Cards for WooCommerce WordPress plugin bef…6.5
Are you affected by CVE-2026-75856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
