dssrf
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting dssrfpage 1 of 1
- CVE-2026-44232HIGHCVSS 8.7EG 8.7✓ Fixed in 1.0.32026-05-12
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, every IPv6 category bypasses is_url_safe. This vulnerability is fixed in 1.0.3.
- CVE-2026-54722HIGHCVSS 8.7EG 8.7✓ Fixed in 1.0.42026-07-30
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the UR…
- CVE-2026-54729HIGHCVSS 8.7EG 8.7✓ Fixed in 1.0.52026-07-31
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address …
Check whether dssrf is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for dssrf CVEs against the assets you own.
Start Free Scan →