compliance-trestle vulnerability

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request Forgery, targeting internal services or cloud metadata endpoints. Versions 3.12.2 and 4.0.3 fix the issue.

Published 14 Aug 2026Updated 18 Sep 20265 sources
CVSS 6.7

Source timeline

CVE record published by NVDView source ↗