{"id":"CVE-2026-54729","title":"DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks","summary":"DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no addres…","severity":"high","cwe":["CWE-918"],"vendor":"dssrf","product":"dssrf","affected":["dssrf <= 1.0.4"],"patched":["dssrf 1.0.5"],"published":"2026-07-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:12:43.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54729","references":[{"url":"https://github.com/HackingRepo/dssrf-js/commit/668c21792cd1252baf779a176aa652e2b4c0067d","label":"security-advisories@github.com"},{"url":"https://github.com/HackingRepo/dssrf-js/pull/102","label":"security-advisories@github.com"},{"url":"https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-5846-7qm3-r52j","label":"security-advisories@github.com"},{"url":"https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-5846-7qm3-r52j","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-5846-7qm3-r52j"}],"tags":["nvd","ghsa","npm"],"epss":0.00363,"epssPercentile":0.30207,"aliases":["GHSA-5846-7qm3-r52j"],"ecosystem":"npm","ingestedAt":"2026-07-31T16:59:59.664Z","slug":"CVE-2026-54729","body":"## Overview\n\nDSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54729)\n\nAffected packages:\n\n- `dssrf <= 1.0.4`\n\nPatched in:\n\n- `dssrf 1.0.5`\n\nSource: https://github.com/advisories/GHSA-5846-7qm3-r52j","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}