THREAT OPS › Threat News › [GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
[GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
GHSA-cpjf-6666-r8fx Severity: high CVE: CVE-2026-61704
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
The existing advisory GHSA-4gp8-rjrq-ch6q / CVE-2026-43897 states that the SSRF issue was fixed in 4.0.1. However, 4.0.3 remains bypassable when the documented resolveDNSHost mitigation is used.
Root cause: The library validates one resolved IP address through res
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-43897cve
- CVE-2026-61704cve
Original source: https://github.com/advisories/GHSA-cpjf-6666-r8fx