CVE-2026-33752 is a Server-Side Request Forgery (SSRF) vulnerability in curl_cffi, a Python wrapper for curl, affecting all versions prior to 0.15.0. The flaw allows attackers to redirect requests to internal IP ranges and cloud metadata endpoints by exploiting curl_cffi's automatic redirect following and unrestricted request routing. The vulnerability is compounded by curl_cffi's TLS impersonation capability, which can mask malicious requests as legitimate browser traffic and potentially circumvent network-based security controls. The vulnerability carries a CVSS score of 8.6 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable. The attack can result in high confidentiality impact through unauthorized access to sensitive internal services and cloud metadata, though integrity and availability are not directly compromised. The EPSS score of 0.00014 indicates very low prevalence among real-world CVEs, suggesting limited current threat activity. There is currently no evidence of active exploitation, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. No public exploit code appears to be widely available, and community attention remains minimal. Organizations using curl_cffi should prioritize upgrading to version 0.15.0 or later to remediate this SSRF risk, particularly in environments handling untrusted URLs or operating in cloud infrastructure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.15.0CPE matchmatch criteria | cpe:2.3:a:lexiforest:curl_cffi:*:*:*:*:*:python:*:* | ||
0.15.0CPE matchmatch criteria | cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta1:*:*:*:python:*:* | ||
0.15.0CPE matchmatch criteria | cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta2:*:*:*:python:*:* | ||
0.15.0CPE matchmatch criteria | cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta3:*:*:*:python:*:* | ||
0.15.0CPE matchmatch criteria | cpe:2.3:a:lexiforest:curl_cffi:0.15.0:beta4:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.