Executive brief
datamodel-code-generator is a tool used to convert data schemas (like OpenAPI or JSON Schema) into Python code. A security flaw allows an attacker to bypass built-in protections and force the tool to connect to internal private servers or cloud metadata services. This could lead to the exposure of sensitive internal data or credentials if the tool is used to process untrusted web addresses or schemas.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in datamodel-code-generator due to a Time-of-Check Time-of-Use (TOCTOU) flaw in its HTTP fetching logic. The tool validates a URL's resolved IP address against a blocklist of private networks but then allows the underlying HTTP client (httpx) to perform a second, independent DNS resolution during the actual connection. An attacker can use a DNS rebinding attack—where a hostname initially resolves to a safe public IP during validation but then resolves to a private IP (e.g., 127.0.0.1 or 169.254.169.254) during the connection—to bypass the 'allow_private_network=False' guard. This allows the tool to fetch and potentially leak data from internal services or cloud metadata endpoints. The issue is fixed in version 0.63.0 by pinning the validated IP address for the duration of the request.
Affected products
- koxudaxi datamodel-code-generator < 0.63.0
Timeline
- 2026-06-12: patched: Fixed in version 0.63.0
- 2026-07-28: disclosed: Public advisory and CVE published