{"id":"CVE-2026-75856","title":"CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks","summary":"CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks an…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"deepseek-tui","product":"deepseek-tui","affected":["deepseek-tui >= 0.8.5, <= 0.8.41","deepseek-tui >= 0.8.5, < 0.8.41","codewhale-tui >= 0.8.41, < 0.8.64","codewhale >= 0.8.41, < 0.8.64"],"patched":["deepseek-tui 0.8.41","codewhale-tui 0.8.64","codewhale 0.8.64"],"published":"2026-08-18","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:32:39.347","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75856","references":[{"url":"https://github.com/Hmbown/CodeWhale/commit/26de44a8bd5051f8f944ea60b2c37ae1d2b7d25e","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-6v2g-fpxh-pmmh","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/codewhale-before-ssrf-bypass-via-dns-pinning-toctou","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Hmbown/CodeWhale/security/advisories/GHSA-6v2g-fpxh-pmmh","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75856"},{"url":"https://github.com/advisories/GHSA-6v2g-fpxh-pmmh"}],"tags":["nvd","ghsa","rust"],"epss":0.0046,"epssPercentile":0.39204,"aliases":["GHSA-6v2g-fpxh-pmmh"],"ecosystem":"rust","ingestedAt":"2026-09-04T18:25:57.068Z","slug":"CVE-2026-75856","body":"## Overview\n\nCodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks and succeed on secondary requests, allowing requests to internal IP addresses and bypassing SSRF mitigations.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-75856)\n\nAffected packages:\n\n- `deepseek-tui >= 0.8.5, <= 0.8.41`\n- `deepseek-tui >= 0.8.5, < 0.8.41`\n- `codewhale-tui >= 0.8.41, < 0.8.64`\n- `codewhale >= 0.8.41, < 0.8.64`\n\nPatched in:\n\n- `deepseek-tui 0.8.41`\n- `codewhale-tui 0.8.64`\n- `codewhale 0.8.64`\n\nSource: https://github.com/advisories/GHSA-6v2g-fpxh-pmmh","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":8203,"id":"CVE-2026-75856","ts":1788919992009,"field":"severity","old":"critical","new":"high"},{"seq":8012,"id":"CVE-2026-75856","ts":1788919280330,"field":"severity","old":"high","new":"critical"},{"seq":7821,"id":"CVE-2026-75856","ts":1788916352152,"field":"severity","old":"critical","new":"high"},{"seq":7630,"id":"CVE-2026-75856","ts":1788915297042,"field":"severity","old":"high","new":"critical"},{"seq":7439,"id":"CVE-2026-75856","ts":1788912712121,"field":"severity","old":"critical","new":"high"},{"seq":7248,"id":"CVE-2026-75856","ts":1788911330975,"field":"severity","old":"high","new":"critical"},{"seq":7052,"id":"CVE-2026-75856","ts":1788909075367,"field":"severity","old":"critical","new":"high"},{"seq":6864,"id":"CVE-2026-75856","ts":1788907391086,"field":"severity","old":"high","new":"critical"},{"seq":6666,"id":"CVE-2026-75856","ts":1788905441722,"field":"severity","old":"critical","new":"high"},{"seq":6484,"id":"CVE-2026-75856","ts":1788903459292,"field":"severity","old":"high","new":"critical"},{"seq":6420,"id":"CVE-2026-75856","ts":1788901910388,"field":"severity","old":"critical","new":"high"}]}