CVE 8.2 HIGH

GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration_CVE-2026-44971

8.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Description

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and capture the GH_TOKEN used by GuardDog. This vulnerability is fixed in .

Basic Information

ID CVE-2026-44971
Source GitHub_M
Published May 27, 2026 at 14:43
Modified May 27, 2026 at 16:09

Affected Product

Vendor DataDog
Product guarddog
Version >= 1.0.0, <= 2.9.0
Affected Versions DataDog guarddog >= 1.0.0, <= 2.9.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.