A high-severity server-side request forgery flaw tracked as CVE-2026-67201 affects the V programming language through version 0.5.2, allowing remote attackers to bypass host-based allowlists. The issue arises from a parser differential between net.urllib and net.http: net.urllib.parse() can validate a seemingly trusted host, while net.http.get() later normalizes a backslash in the URL authority field and connects to an internal destination instead.
The vulnerability was addressed in merged commit 85859f0 through a change titled "net.urllib: reject backslashes in URL authorities", with accompanying tests for vlib/net/urllib and vlib/net/http. Published guidance recommends upgrading to a patched release and reviewing applications to ensure URL normalization and host validation are performed consistently across parsing and request-handling components.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The V project merged commit 85859f0 into master to harden net.urllib by rejecting backslashes in URL authority fields, with related tests for net.urllib and net.http. This change is identified as the fix for the later-tracked SSRF bypass issue.
CVE-2026-67201 was publicly disclosed as a high-severity SSRF bypass affecting V through version 0.5.2. The flaw was described as a parser differential between net.urllib and net.http that could let attackers bypass host-based allowlists by using a backslash in the URL authority section.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.