CVE-2026-105800Low· 3.7▾ Sunliti18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that beg…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
i18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that begins directly with {{lng}} or {{ns}} can make colon-based input become an absolute URL or, in browsers, make a double-slash namespace become a protocol-relative URL. The resulting request can leave the intended origin and cause URL injection or server-side request forgery. The default /locales/{{lng}}/{{ns}}.json template and templates with a leading path or origin are not affected because the placeholder does not occupy the URL's structural beginning. This issue is fixed in version 4.0.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
i18next-http-backend < 4.0.2Patched in:
i18next-http-backend 4.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14884High· 7.2A vulnerability was detected in D-Link DIR-605 202WWB03
CVE-2026-101018Medium· 4.7A vulnerability was determined in dayrui XunruiCMS up to 4.7.2
CVE-2026-101013High· 7.3A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be
CVE-2026-101010Medium· 4.7A vulnerability was identified in aaPanel BaoTa up to 11.8.0
CVE-2026-101011Medium· 4.7A security flaw has been discovered in aaPanel BaoTa up to 11.8.0
CVE-2026-101012High· 7.3A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be