Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105800— i18next-http-backend incomplete URL validation permits SSRF

Quick assessment

Affected
i18next i18next-http-backend
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

i18next-http-backend 是 i18next 的后端层,用于在 Node.js、浏览器和 Deno 环境中加载翻译资源。在版本 4.0.2 之前,如果攻击者控制的 (语言)或 (命名空间)值被插入到自定义的 或 中,且该路径以 或 开头,则基于冒号(: // /locales/{{lng}}/{{ns}}.json`,也不影响包含前导路径或明确指定源地址的模板,因为在这类情况下,占位符并未位于 URL 的结构起始位置。 此问题已在版本 4.0.2 中修复。

CVSS 3.7 · Low

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105800

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
i18next-http-backend incomplete URL validation permits SSRF
Source: CVE Program / CVE List V5
Vulnerability Description
i18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that begins directly with {{lng}} or {{ns}} can make colon-based input become an absolute URL or, in browsers, make a double-slash namespace become a protocol-relative URL. The resulting request can leave the intended origin and cause URL injection or server-side request forgery. The default /locales/{{lng}}/{{ns}}.json template and templates with a leading path or origin are not affected because the placeholder does not occupy the URL's structural beginning. This issue is fixed in version 4.0.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
i18next i18next-http-backend < 4.0.2 -

II. Public POCs for CVE-2026-105800

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105800

请登录查看更多情报信息。

Other References for CVE-2026-105800 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105800

No comments yet


Leave a comment