Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-40072 Details

Description

web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web3.py implements CCIP Read / OffchainLookup (EIP-3668) by performing HTTP requests to URLs supplied by smart contracts in offchain_lookup_payload["urls"]. The implementation uses these contract-supplied URLs directly (after {sender} / {data} template substitution) without any destination validation. CCIP Read is enabled by default (global_ccip_read_enabled = True on all providers), meaning any application using web3.py's .call() method is exposed without explicit opt-in. This results in Server-Side Request Forgery (SSRF) when web3.py is used in backend services, indexers, APIs, or any environment that performs eth_call / .call() against untrusted or user-supplied contract addresses. A malicious contract can force the web3.py process to issue HTTP requests to arbitrary destinations, including internal network services and cloud metadata endpoints. This vulnerability is fixed in 7.15.0 and 8.0.0b2.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-918Server-Side Request Forgery (SSRF)[email protected]

Affected Products

ProductVersions
apeworx web3.py
>= 6.1.0, < 7.15.0
6.0.0 -
6.0.0 beta10
6.0.0 beta11
6.0.0 beta3

CPE

  • cpe:2.3:a:apeworx:web3.py:*:*:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:-:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta10:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta11:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta3:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta4:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta5:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta6:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta7:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta8:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:6.0.0:beta9:*:*:*:python:*:*
  • cpe:2.3:a:apeworx:web3.py:8.0.0:beta1:*:*:*:python:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-40072
NVD Published Date:
Apr 9, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2026-40072 Details - Not Deferred