link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
High severity
GitHub Reviewed
Published
Jun 23, 2026
in
OP-Engineering/link-preview-js
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Aug 20, 2026
Published to the GitHub Advisory Database
Sep 2, 2026
Reviewed
Sep 2, 2026
Last updated
Sep 2, 2026
The existing advisory GHSA-4gp8-rjrq-ch6q / CVE-2026-43897 states that the SSRF issue was fixed in 4.0.1. However, 4.0.3 remains bypassable when the documented resolveDNSHost mitigation is used.
Root cause:
The library validates one resolved IP address through resolveDNSHost, but later performs fetch() against the original hostname without pinning the connection to the validated IP. An attacker-controlled DNS server can return a public IP during validation and a loopback/internal IP during the final connection.
Impact:
This allows an attacker to bypass the documented SSRF mitigation and make the server-side fetch reach loopback or internal addresses under DNS rebinding conditions.
This appears to be either an incomplete fix for CVE-2026-43897 or a new DNS rebinding SSRF bypass affecting the latest version.
The PoC was reproduced in a local-only controlled environment to avoid targeting production or third-party systems. Evidence and reproduction details can be provided privately.
References