External risk intelligence

Safeurl TOCTOU Race Condition Allows Unauthorized Network Access.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-77972

The vulnerability resides in a URL validation library. While such libraries are often used in internet-facing applications to process user-supplied URLs, the library itself is a backend component. Its actual exposure depends on how a specific application implements it, rather than being inherently internet-facing by design.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in the safeurl library. An attacker could potentially manipulate DNS responses to bypass validation and reach internal network destinations, even if those destinations were initially rejected. This could occur when the library resolves hostnames, as the validation verdict is separate from the final address used by HTTP clients.

  • Bypass security checks by manipulating DNS.
  • Matters if safeurl is used for URL validation.
  • Confirm if your applications use this library.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by controlling DNS responses for a hostname. This allows them to trick the library into connecting to internal network destinations that should have been blocked after an initial validation step. This occurs because the library resolves a hostname twice, and an attacker can manipulate the DNS in between these lookups.

  • Attacker controls DNS for a hostname.
  • Triggers a TOCTOU race condition in the library.
  • Bypasses network destination validation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker controlling DNS responses to bypass intended network access restrictions. When the library validates a hostname, it may subsequently resolve the hostname again, potentially reaching internal network destinations that were initially rejected. This could occur when DNS records have short lifetimes or rotate between addresses.

  • Internal network destinations.
  • Via manipulated DNS responses.
  • Unauthorized network access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a URL validation library impacts applications that use it to process hostnames, potentially allowing unauthorized access to internal network resources. Responsibility likely falls to application owners and platform teams who manage these integrations, with initial steps involving inventorying where the library is used, assessing its reachability and criticality, and identifying the specific application owners for remediation planning.

  • Application owners and platform teams.
  • Verify all deployments of the library.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Slab safeurl library?

Safeurl is an Elixir library designed for URL validation. Developers integrate it into applications to ensure that user-provided URLs point to safe or approved locations. By checking hostnames against allowed criteria, it helps prevent applications from making requests to restricted or malicious web destinations.

What is the CWE-367 vulnerability in CVE-2026-77972?

This is a Time-of-check Time-of-use (TOCTOU) race condition. It occurs because the library performs two separate lookups for the same hostname. It validates the address during the first lookup, but the final HTTP request uses the result of a second, independent resolution. If the hostname's DNS response changes between these two steps, the validation verdict no longer applies to the actual destination reached.

How does an attacker trigger this race condition?

An attacker must control the authoritative DNS server for the hostname being validated. By providing a permitted IP address for the initial check and a restricted internal address for the subsequent request, they cause the library to connect to a forbidden destination. Note that simply having a hostname with rotating IP addresses or short record lifetimes can also trigger this behavior without malicious intent.

How does Halo Surface Signal categorize this risk?

Halo Surface Signal labels this as a backend component risk. Because safeurl is a library, its exposure depends on how your specific application uses it. If your software uses safeurl to process user-supplied URLs that may eventually touch internal network resources, the potential for unauthorized access exists, regardless of whether the library is directly internet-facing.

What steps should I take to address CVE-2026-77972?

Start by identifying all applications in your environment that include the safeurl library. Once you have an inventory, coordinate with the respective application owners to assess how these services use the library to validate URLs. Use this information to prioritize applications that handle sensitive network paths and plan for necessary updates or implementation changes.

References