{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dssrf--1.0.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-54729"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dssrf (\u003c= 1.0.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe dssrf npm package contains a security vulnerability (CVE-2026-54729) that allows an attacker to bypass URL validation and perform server-side request forgery (SSRF). This issue specifically affects environments that utilize 1.1.1.1 as the configured DNS resolver. The vulnerability exists within the is_url_safe function, which fails to handle NXDOMAIN responses correctly. When the library attempts to resolve a target address, it does not properly fall back or account for cases where the DNS query for a seemingly malicious or internal address returns an NXDOMAIN result. As a consequence, the validation logic erroneously evaluates requests to localhost or other internal endpoints as safe. This vulnerability allows an attacker to interact with services on the host machine or internal network that would otherwise be protected by the library's URL filtering mechanisms. This impacts applications relying on dssrf for input sanitization of user-provided URLs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to perform SSRF attacks, potentially leading to unauthorized access to internal services, sensitive metadata endpoints, or administrative interfaces running on the same host or network as the application using the affected dssrf package.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the dssrf npm package to version 1.5.0 or later to include the fix for CVE-2026-54729.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, review application configurations to ensure DNS resolution for restricted domains is performed using robust internal resolvers that do not exhibit the same handling behavior as 1.1.1.1 in this context.\u003c/li\u003e\n\u003cli\u003eImplement additional network-level ingress/egress filtering to prevent the application server from initiating connections to localhost or internal RFC1918 address space.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T19:29:34Z","date_published":"2026-07-31T19:29:34Z","id":"https://feed.craftedsignal.io/briefs/2026-07-dssrf-ssrf/","summary":"The dssrf npm package (versions 1.0.4 and earlier) fails to correctly validate URLs when using 1.1.1.1 as a DNS resolver, incorrectly treating localhost as safe and enabling server-side request forgery (SSRF) when NXDOMAIN responses occur.","title":"SSRF Vulnerability in dssrf npm Package via DNS Resolver Logic","url":"https://feed.craftedsignal.io/briefs/2026-07-dssrf-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Dssrf (\u003c= 1.0.4)","version":"https://jsonfeed.org/version/1.1"}