CVE-2026-54722CWE-76

dssrf: there a critical security bug with remove_at_symbol_in_string

High · published July 30, 2026

CVSS v4.0
8.7
EPSS
0%
Percentile
25.5
In the wild
Unconfirmed
What it is

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00328 · 25.5th percentile
Weakness
CWE-76 · Improper Neutralization of Equivalent Special Elements
Published
2026-07-30T16:27Z
EPSS history
Timeline
  • 30 JUL 16:27Z
    dssrf: there a critical security bug with remove_at_symbol_in_string
    cvelistv5