Feed/CVE-2026-54452
CVE-2026-54452MEDIUMCVSS 0.0

safeurl is Missing IPv6 CIDR Ranges in Blocklist

Published Jul 15, 2026·Updated Jul 15, 2026

NVD Description

The `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RFC 8215) - `5f00::/16`: Segment Routing (SRv6) SIDs (RFC 9602) - `3fff::/20`: documentation prefix (RFC 9637) - `100:0:0:1::/64`: Dummy IPv6 Prefix (RFC 9780) ### Impact If exploited, an attacker would potentially be able to reach resources hosted on the IPs residing in the missing ranges. ### Workarounds Disable IPv6 by setting `EnableIPv6(false)`. This is the default behavior of the library. ### Resolution Upgrade to v0.2.4 ### Credits safeurl thanks @tonghuaroot for reporting.

Affected Packages (1)

github.com/doyensec/safeurlGO
Fixed in 0.2.4

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free