dssrf-js vulnerability

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.

Published 31 Jul 2026Updated 10 Sep 20264 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.