Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CodeWhale SSRF bypass via DNS pinning TOCTOU

A time-of-check-time-of-use (TOCTOU) vulnerability in CodeWhale's DNS pinning implementation allows attackers to bypass SSRF mitigations by controlling a custom DNS server to fail initial requests and succeed on secondary requests.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Allows full bypass of SSRF mitigations when attacker controls DNS resolver, enabling access to local resources.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-6v2g-fpxh-pmmh