CVE-2024-11168General

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-02: 1Technical Details · 2026-04-02: 104-02
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Averlon@Averlon_ai
    General

    CVE-2024-11168 has a CVSS score of 3.7. Low severity. No known exploits. Not internet-facing. It sits in most backlogs indefinitely. It’s an SSRF flaw in Python’s urllib. On its own, not urgent. On this asset, it’s different. The node has an IAM role attached. The metadata service is reachable. IMDSv1 is enabled. Now it’s on a chain. The attacker hits the node. Pulls credentials through SSRF. Moves laterally. Downloads data. Exfiltrates it. Six steps. The last hop is the internet. The finding didn’t change. The context did. Context decides what gets fixed first. That’s Remediation Ops.

    Post summary

    CVE-2024-11168 is an SSRF vulnerability with low severity; while no exploitation or patch is reported, the description highlights the risk of credential theft and lateral movement driven by the access to the metadata service.

    0001052
    36 followersView on X

Explore more