top of page
perceptive_background_267k.jpg

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accep…

Published:

27 juli 2026 om 22:00:00

Alert date:

28 juli 2026 om 23:04:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A server-side request forgery (SSRF) vulnerability was discovered in the datamodel-code-generator Python library, affecting versions 0.9.1 through 0.61.0. The vulnerability exists in src/datamodel_code_generator/http.py, where the http.get_body function accepts --url targets and redirect chain targets without validating the host or IP address. This lack of validation allows attackers to forge requests against loopback addresses, private networks, link-local addresses, metadata services, and other network-accessible resources. The flaw could be exploited to access internal infrastructure, cloud metadata endpoints (such as AWS IMDSv1), or other sensitive internal services. The issue has been patched in version 0.61.0 of the library. Users are strongly advised to upgrade to version 0.61.0 or later to mitigate the risk. The fix is available via the official GitHub repository commit and release.

Technical details

Mitigation steps:

Affected products:

datamodel-code-generator

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page