External risk intelligence

Slab safeurl SSRF Vulnerability Allows Internal Network Access

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-77866

This is an SSRF vulnerability in a URL validation library. While it is network-accessible via applications that use it, the library itself is a backend component rather than a standalone network service or edge appliance. Its exposure is strictly dependent on how developers implement it within their specific applications.

Server-Side Request Forgery

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in the safeurl library allows an attacker to bypass configured restrictions on accessing internal network destinations by manipulating how URLs are formatted. While the library is intended to enhance security by validating URLs, a flaw in its handling of IPv4 and IPv6 addresses means that certain destinations, even if blocked, can still be reached.

  • A flaw lets blocked internal network addresses be reached.
  • This could expose internal systems if the library is used.
  • Assess if your use of this library is affected.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this Server-Side Request Forgery vulnerability if they can control a URL that is processed by the safeurl library. By manipulating the format of the URL, particularly by using IPv6 addressing or hostnames that resolve to non-IPv4 addresses, an attacker could bypass the library's intended restrictions and cause the application to send requests to internal network destinations. This bypass is possible because the library's validation logic only correctly checks IPv4 addresses against reserved ranges and blocklists.

  • No authentication or privileges needed.
  • Attacker crafts a URL to bypass restrictions.
  • Unauthorized access to internal network resources.

Live Threat

Current exploitation, exposure, and threat context

A Server-Side Request Forgery vulnerability in the Slab safeurl library could allow an attacker to bypass configured blocklists and access internal network destinations when certain URL formats are used and the library is not configured with an allowlist. This occurs because only IPv4 addresses are matched against reserved ranges and blocklists, while other address formats, including IPv6 or hosts resolving to no IPv4 address, may be accepted.

  • Internal network destinations.
  • Validated URLs reach internal destinations.
  • Unauthorized network access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery (SSRF) vulnerability requires action from teams responsible for applications that use the `safeurl` library. The first practical step is to identify all instances of this library, confirm if they are business-critical or reachable, and then determine the accountable owner for remediation planning.

  • Application owners should be responsible.
  • Verify application reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Slab safeurl library?

Slab safeurl is an Elixir-based utility library designed to help developers validate URLs. It is commonly used as a backend component in applications to ensure that outgoing requests are directed only to safe, authorized destinations, effectively acting as a guardrail against unauthorized network requests.

How does CVE-2026-77866 work as an SSRF vulnerability?

This vulnerability, classified as Server-Side Request Forgery (CWE-918), stems from a flaw in how the library filters addresses. Because the validation logic only inspects IPv4 addresses, it fails to evaluate IPv6 addresses or certain hostnames. An attacker can exploit this oversight to trick an application into connecting to internal services that should have been blocked, effectively bypassing the intended security restrictions.

When can an attacker trigger this vulnerability?

An attacker can trigger this when they have the ability to supply or influence a URL that the application processes using this library. The flaw is not triggered if the application is configured to use an allowlist, as the library rejects any unmatched addresses in that mode. The vulnerability specifically affects configurations relying solely on blocklists or reserved range filtering.

Do I need to worry if my application uses Slab safeurl?

Whether this poses a risk depends on your implementation. According to Halo Surface Signal, because this is a backend library rather than a standalone appliance, your exposure depends on how you have integrated it. If your application processes user-provided URLs that can reach internal network resources, it is more critical to assess the impact of this bypass.

What is the first step to address CVE-2026-77866?

You should start by identifying every application or service within your infrastructure that includes the safeurl library. Once you have an inventory, verify which of these are reachable from external sources and determine their business criticality. This provides the context needed for your engineering team to prioritize and plan the necessary updates to secure your internal network.

References