PT-2026-3253 · Validator.Nu · Nu Html Checker

Oscar Uribe

·

Published

2026-01-16

·

Updated

2026-03-17

·

CVE-2025-15104

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nu Html Checker versions prior to commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd
Description The Nu Html Checker (validator.nu) is susceptible to a restriction bypass that enables remote attackers to initiate arbitrary HTTP/HTTPS requests to internal resources, including services on localhost. The application employs hostname-based protections to prevent direct access to localhost and 127.0.0.1, but these safeguards can be circumvented through DNS rebinding techniques or by utilizing domains that resolve to loopback addresses. This allows an attacker to potentially access internal systems and data.
Recommendations Update Nu Html Checker to a version after commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-15104
GHSA-FCCG-7W3P-W66F

Affected Products

Nu Html Checker