PT-2026-66529 · Hackingrepo · Dssrf-Js

CVE-2026-54722

·

Publicado

2026-07-30

·

Atualizado

2026-07-30

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is url safe in src/helpers.ts strips the @ userinfo delimiter with remove at symbol in string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-54722

Produtos afetados

Dssrf-Js