Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33752

29
FAUCET Score

CVE-2026-33752 is a Server-Side Request Forgery (SSRF) vulnerability in curl_cffi, a Python wrapper for curl, affecting all versions prior to 0.15.0. The flaw allows attackers to redirect requests to internal IP ranges and cloud metadata endpoints by exploiting curl_cffi's automatic redirect following and unrestricted request routing. The vulnerability is compounded by curl_cffi's TLS impersonation capability, which can mask malicious requests as legitimate browser traffic and potentially circumvent network-based security controls. The vulnerability carries a CVSS score of 8.6 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable. The attack can result in high confidentiality impact through unauthorized access to sensitive internal services and cloud metadata, though integrity and availability are not directly compromised. The EPSS score of 0.00014 indicates very low prevalence among real-world CVEs, suggesting limited current threat activity. There is currently no evidence of active exploitation, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. No public exploit code appears to be widely available, and community attention remains minimal. Organizations using curl_cffi should prioritize upgrading to version 0.15.0 or later to remediate this SSRF risk, particularly in environments handling untrusted URLs or operating in cloud infrastructure.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.15.0CPE matchmatch criteria
cpe:2.3:a:lexiforest:curl_cffi:*:*:*:*:*:python:*:*
0.15.0CPE matchmatch criteria
cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta1:*:*:*:python:*:*
0.15.0CPE matchmatch criteria
cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta2:*:*:*:python:*:*
0.15.0CPE matchmatch criteria
cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta3:*:*:*:python:*:*
0.15.0CPE matchmatch criteria
cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta4:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: curl_cffiFixed in: 0.15.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-qw2m-4pqf-rmpphigh

curl_cffi: Redirect-based SSRF leads to internal network access in curl_cffi (with TLS impersonation bypass)

Apr 3, 2026

References

github.com / lexiforest/curl_cffi/security/advisories/GHSA-qw2m-4pqf-rmpp
ExploitVendor Advisory