CVE-2026-54691General

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link-local, metadata, and other network-accessible resources. This issue is fixed in version 0.61.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-29)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 1Mentions · 2026-07-29: 2Technical Details · 2026-07-29: 106-2307-29
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-231
General1
2026-07-292
Disclosure1General1
Full discourse3 posts
  • Hamza@TheGr1ffyn
    General

    CVE-2026-54621 CVE-2026-54653 CVE-2026-54654 CVE-2026-54655 CVE-2026-54656 CVE-2026-54690 CVE-2026-54691 CVE-2026-55415 CVE-2026-55389 CVE-2026-55390 CVE-2026-55391 CVE-2026-55403

    Post summary

    The content merely lists a series of CVE identifiers without providing additional context, code, or details about the vulnerabilities.

    1000061
    132 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54691 datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --u… https://www.cve.org/CVERecord?id=CVE-2026-54691 ----- Traducción: CVE-2026-54691 dat… http://infoflow.cloud`

    Post summary

    The text briefly announces CVE‑2026‑54691 and references affected versions of datamodel‑code‑generator, linking to the CVE record. No additional technical, exploit, or mitigation information is provided.

    0000024
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54691 datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --u… https://www.cve.org/CVERecord?id=CVE-2026-54691

    Post summary

    The post cites a CVE in datamodel‑code‑generator, indicating an affected function, but offers no PoC, exploit, or patch details.

    000001.1K
    57.9K followersView on X

Explore more