-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0225 ============================================================ Advisory-ID: 0xCERT-2026-0225 Severity: Medium Published: 2026-04-04T06:38:11.000Z Updated: 2026-10-08T22:48:28.126Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0225 Title: web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling Summary - ------- web3.py: SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling. web3.py implements CCIP Read / OffchainLookup (EIP-3668) by performing HTTP requests to URLs supplied by smart contracts in offchainlookuppayload["urls"]. Details - ------- Summary web3.py implements CCIP Read / OffchainLookup (EIP-3668) by performing HTTP requests to URLs supplied by smart contracts in offchainlookuppayload["urls"]. The implementation uses these contract-supplied URLs directly (after {sender} / {data} template substitution) without any destination validation: - No restriction to https:// (and no opt-in gate for http://) - No hostname or IP allowlist - No blocking of private/reserved IP ranges (loopback, link-local, RFC1918) - No redirect target validation (both requests and aiohttp follow redirects by default) CCIP Read is enabled by default (globalccipreadenabled = True on all providers), meaning any application using web3. Affected - - web3 (pip) >= 6.0.0b3, < 7.15.0 — fixed in 7.15.0 - - web3 (pip) = 8.0.0b1 — fixed in 8.0.0b2 Severity Medium (CVSS 6.9), as rated by the upstream advisory. Recommended actions - - Upgrade web3 to 7.15.0 or later - - Upgrade web3 to 8.0.0b2 or later Source & attribution This 0xCERT advisory summarises GHSA-5hr4-253g-cpx2 / CVE-2026-40072 from the GitHub Advisory Database, credited upstream to Nadav0077: https://github.com/advisories/GHSA-5hr4-253g-cpx2. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-5hr4-253g-cpx2 - - CVE-2026-40072 - - https://github.com/ethereum/web3.py/security/advisories/GHSA-5hr4-253g-cpx2 - - https://nvd.nist.gov/vuln/detail/CVE-2026-40072 - - https://github.com/ethereum/web3.py/commit/b1c57bb0a124359c9902daaefab4d8af7c3c4c1e Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9V0JEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcme7REJuhGAaxpfVbZ6QeCj7D25vB16CEmqX2Gd0 LaF8ThYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAACVyAEA3fnpCN9xfBvJrap0 1BHPwBZSmDP0eOIsgemX8Jbcj3UBAPTzGmJ5dkIrXJskTlZ1gKqMkgfuvaGP x20V8/8Q+eUL =fNi+ -----END PGP SIGNATURE-----