link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
漏洞描述
The existing advisory GHSA-4gp8-rjrq-ch6q / CVE-2026-43897 states that the SSRF issue was fixed in 4.0.1. However, 4.0.3 remains bypassable when the documented resolveDNSHost mitigation is used. Root cause: The library validates one resolved IP address through resolveDNSHost, but later performs fetch() against the original hostname without pinning the connection to the validated IP. An attacker-controlled DNS server can return a public IP during validation and a loopback/internal IP during the final connection. Impact: This allows an attacker to bypass the documented SSRF mitigation and make the server-side fetch reach loopback or internal addresses under DNS rebinding conditions. This appears to be either an incomplete fix for CVE-2026-43897 or a new DNS rebinding SSRF bypass affecting the latest version. The PoC was reproduced in a local-only controlled environment to avoid targeting production or third-party systems. Evidence and reproduction details can be provided privately. Source Code Location: https://github.com/OP-Engineering/link-preview-js Affected Packages: - npm:link-preview-js, affected <= 4.0.3, patched in 4.0.4 CWEs: - CWE-918: Server-Side Request Forgery (SSRF) CVSS: - Primary: score 7.5, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS_V3: score 7.5, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References: - https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-cpjf-6666-r8fx - https://nvd.nist.gov/vuln/detail/CVE-2026-61704 - https://github.com/OP-Engineering/link-preview-js/pull/181 - https://github.com/OP-Engineering/link-preview-js/commit/6ee25043dd60b097eb70b4ce049aac94b28239e3 - https://github.com/OP-Engineering/link-preview-js/commit/f3a3dd84adbb9d32d06a933f44ff3eaa837f9a12 - https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.4 - https://github.com/advisories/GHSA-cpjf-6666-r8fx