Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Op-engineering
Op-engineering link-preview-js |
|
| Vendors & Products |
Op-engineering
Op-engineering link-preview-js |
Thu, 20 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4. | |
| Title | link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897 | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T15:03:17.040Z
Reserved: 2026-07-10T18:51:13.919Z
Link: CVE-2026-61704
Updated: 2026-08-25T15:03:11.952Z
Status : Received
Published: 2026-08-20T17:18:51.940
Modified: 2026-08-25T15:16:35.813
Link: CVE-2026-61704
No data.
OpenCVE Enrichment
Updated: 2026-08-20T20:30:05Z