Lexiforest develops curl_cffi, a Python HTTP client library that wraps curl functionality, where the observed vulnerability profile centers on server-side request forgery conditions in request handling. This niche library's exposure reflects the inherent risks of implementing HTTP clients that must safely validate and restrict the destinations reachable by downstream application code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lexiforest over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33752HIGH curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libc | Apr 6, 2026 | 8.6 | 29 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lexiforest.
Media articles that mention a CVE ID that affects a product developed by Lexiforest — matched by CVE ID, not by vendor name.