Back to CVE List

CVE-2026-44232

HIGH SEVERITY

Vulnerability Description

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.3.0, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.3.0.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-791
Source
GitHub
Vendor
npm
Product
dssrf

External References

Discussion (1)

Add Comment

The mistake
<h1>It is a mistake, that our ipv6 logic is confusing, the code looks validating but it is buggy</h1>

Reply to The mistake