THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897

[GHSA] GHSA-cpjf-6666-r8fx (high) — link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897

medgithub_advisoriesPublished 2026-09-02

GHSA-cpjf-6666-r8fx Severity: high CVE: CVE-2026-61704

link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897

The existing advisory GHSA-4gp8-rjrq-ch6q / CVE-2026-43897 states that the SSRF issue was fixed in 4.0.1. However, 4.0.3 remains bypassable when the documented resolveDNSHost mitigation is used.

Root cause: The library validates one resolved IP address through res

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cpjf-6666-r8fx