compliance-trestle vulnerability

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue.

Published 14 Aug 2026Updated 18 Sep 20265 sources
CVSS 6.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.