Description
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 26.1.11
References
Could your website be exposed too?
SmartScanner can check your website for Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability and gives you actionable findings to investigate.
Start a free scanRelated Issues
- google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability - CVE-2023-48711
- Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url - CVE-2022-2900
- Strapi Server-Side Request Forgery (SSRF) - CVE-2024-37818
- Nuxt Icon affected by a Server-Side Request Forgery (SSRF) - CVE-2024-42352


