VYPR

PyPI package

compliance-trestle

pkg:pypi/compliance-trestle

Vulnerabilities (1)

  • CVE-2026-52776higAug 12, 2026
    affected < 4.1.0fixed 4.1.0

    ### Summary `compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can be