HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
- Severity:
- High
Description
Multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication.
Recommendation
Update the @haxtheweb/open-apis package to the latest compatible version. Followings are version details:
- Affected version(s): < 26.0.0
- Patched version(s): 26.0.0
References
Related Issues
- Payload: Server-Side Request Forgery (SSRF) in External File URL Uploads - CVE-2026-27567
- pdfmake is vulnerable to server-side request forgery (SSRF) - CVE-2026-26801
- Flowise affected by Server-Side Request Forgery (SSRF) in HTTP Node Leading to Internal Network Access - CVE-2026-31829
- @better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints - CVE-2026-53513
You might also like:
- Tags:
- npm
- @haxtheweb/open-apis
Anything's wrong? Let us know Last updated on June 09, 2026


