Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Op-engineering
Op-engineering link-preview-js |
|
| Vendors & Products |
Op-engineering
Op-engineering link-preview-js |
Thu, 20 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4. | |
| Title | link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-20T16:21:10.450Z
Reserved: 2026-07-10T18:51:13.919Z
Link: CVE-2026-61704
No data.
Status : Received
Published: 2026-08-20T17:18:51.940
Modified: 2026-08-20T17:18:51.940
Link: CVE-2026-61704
No data.
OpenCVE Enrichment
Updated: 2026-08-20T20:30:05Z