


Perceptive Security
SOC/SIEM Consultancy

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accep…
Published:
28 July 2026 at 00:00:00
Alert date:
29 July 2026 at 01:04:30
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A server-side request forgery (SSRF) vulnerability was discovered in the datamodel-code-generator Python library, affecting versions 0.9.1 through 0.61.0. The vulnerability exists in src/datamodel_code_generator/http.py, where the http.get_body function accepts --url targets and redirect chain targets without validating the host or IP address. This lack of validation allows attackers to forge requests against loopback addresses, private networks, link-local addresses, metadata services, and other network-accessible resources. The flaw could be exploited to access internal infrastructure, cloud metadata endpoints (such as AWS IMDSv1), or other sensitive internal services. The issue has been patched in version 0.61.0 of the library. Users are strongly advised to upgrade to version 0.61.0 or later to mitigate the risk. The fix is available via the official GitHub repository commit and release.
Technical details
Mitigation steps:
Affected products:
datamodel-code-generator
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54691
https://github.com/koxudaxi/datamodel-code-generator/commit/5fdba4a09f2d7a9996a504975b7ef7d63e3715bb
https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.61.0
https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-rfr2-mq9m-x2qx
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
