<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:46:48.259911+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342832</id>
    <title>EUVD-2026-342832</title>
    <updated>2026-10-06T06:46:48.308605+00:00</updated>
    <content>EUVD-2026-342832</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342832"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54722</id>
    <title>fkie_cve-2026-54722</title>
    <updated>2026-10-06T06:46:48.308643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cg4g-m8jx-vjv2</id>
    <title>GHSA-cg4g-m8jx-vjv2 — dssrf has an SSRF bypass with remove_at_symbol_in_string</title>
    <updated>2026-10-06T06:46:48.308677+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dssrf</p>
<p>## Summary</p>
<p>`is_url_safe` in v1.0.3 contains an SSRF bypass. `remove_at_symbol_in_string` is applied to the raw URL string **before** `new URL()` parses it. This strips the `@` that separates userinfo from host, corrupting the hostname so internal IPs are never checked.</p>
<p>## Vulnerability</p>
<p>In `helpers.ts`, `is_url_safe` does:</p>
<p>```ts
u = remove_at_symbol_in_string(u);   // strips ALL '@' from the raw string
// ...
const parsed = new URL(u);
const hostname = parsed.hostname;    // resolved from the corrupted string
```</p>
<p>### What happens step by step</p>
<p>Input: `http://evil.com@127.0.0.1/`</p>
<p>1. `remove_at_symbol_in_string` → `http://evil.com127.0.0.1/`
2. `new URL(...)` → `hostname = "evil.com127.0.0.1"`
3. Not a bare IP, not IPv6 → passes all IP checks
4. `is_hostname_resolve_to_internal_ip("evil.com127.0.0.1")` → NXDOMAIN → returns false
5. **Result: `true` (safe)** — but any HTTP client using the *original* URL connects to `127.0.0.1`</p>
<p>### Proof of Concept</p>
<p>```js
import nock from 'nock';
import { got } from 'got';
import { is_url_safe } from 'dssrf';</p>
<p>// Simulate an internal server at 10.0.0.1 that returns secret data
nock('http://10.0.0.1:80').persist().get('/').reply(200, 'SECRET_DATA');</p>
<p>const BYPASS_URL = 'http://2@10.0.0.1/';
const PLAIN_URL  = 'http://10.0.0.1/';</p>
<p>// dssrf should block both — it only blocks the plain one
console.log('--- dssrf validator ---');
console.log(`is_url_safe('${PLAIN_URL}')   =`, await is_url_safe(PLAIN_URL),  '← correctly blocked');
console.log(`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cg4g-m8jx-vjv2"/>
  </entry>
</feed>
