PT-2026-3253 · Validator.Nu · Nu Html Checker
Oscar Uribe
·
Published
2026-01-16
·
Updated
2026-03-17
·
CVE-2025-15104
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nu Html Checker versions prior to commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd
Description
The Nu Html Checker (validator.nu) is susceptible to a restriction bypass that enables remote attackers to initiate arbitrary HTTP/HTTPS requests to internal resources, including services on localhost. The application employs hostname-based protections to prevent direct access to localhost and 127.0.0.1, but these safeguards can be circumvented through DNS rebinding techniques or by utilizing domains that resolve to loopback addresses. This allows an attacker to potentially access internal systems and data.
Recommendations
Update Nu Html Checker to a version after commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nu Html Checker