GHSA-fccg-7w3p-w66f

Suggest an improvement
Source
https://github.com/advisories/GHSA-fccg-7w3p-w66f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-fccg-7w3p-w66f/GHSA-fccg-7w3p-w66f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fccg-7w3p-w66f
Published
2026-01-16T15:31:25Z
Modified
2026-01-16T20:16:14.434304Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:P CVSS Calculator
Summary
Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
Details

Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-16T19:57:33Z",
    "severity": "MODERATE",
    "nvd_published_at": "2026-01-16T14:15:54Z",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Maven / nu.validator:validator

Package

Name
nu.validator:validator
View open source insights on deps.dev
Purl
pkg:maven/nu.validator/validator

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
26.1.11

Affected versions

15.*

15.3.10
15.3.11
15.3.12
15.3.14
15.3.28
15.4.12
15.6.29

16.*

16.1.1
16.3.3
16.6.18
16.6.20
16.6.29

17.*

17.0.0
17.0.1
17.1.0
17.2.0
17.2.1
17.3.0
17.7.0
17.9.0
17.11.0
17.11.1

18.*

18.3.0
18.7.22
18.7.23
18.8.29
18.11.5

20.*

20.3.16
20.6.30
20.7.2

25.*

25.10.27
25.10.29
25.10.30
25.10.31
25.11.1
25.11.2
25.11.3
25.11.4
25.11.5
25.11.6
25.11.7
25.11.8
25.11.17
25.11.19
25.11.20
25.11.25
25.11.27
25.11.28
25.11.29
25.11.30
25.12.1
25.12.2
25.12.5
25.12.6
25.12.7
25.12.8
25.12.9
25.12.10
25.12.11
25.12.12
25.12.14
25.12.16
25.12.17
25.12.18
25.12.19
25.12.20
25.12.21
25.12.22
25.12.23
25.12.24
25.12.25
25.12.26
25.12.27
25.12.28
25.12.29
25.12.30
25.12.31

26.*

26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.7
26.1.9
26.1.11

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-fccg-7w3p-w66f/GHSA-fccg-7w3p-w66f.json"

npm / vnu-jar

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
26.1.11

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-fccg-7w3p-w66f/GHSA-fccg-7w3p-w66f.json"