All 3 CVE vulnerabilities found in i18next-http-middleware, with AI-generated Chinese analysis, references, and POCs.
Vendor: i18next
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-42353 | Path traversal / SSRF in i18next-http-middleware via user-controlled language and namespace parameters CWE-22 | 8.2 | High | 2026-05-08 |
| CVE-2026-41683 | HTTP response splitting and DoS in i18next-http-middleware via unsanitised Content-Language header CWE-79 | 8.6 | High | 2026-05-08 |
| CVE-2026-41690 | Prototype pollution and path traversal in i18next-http-middleware via user-controlled language and namespace parameters CWE-22 | 8.6 | High | 2026-05-08 |
All 3 known CVE vulnerabilities affecting i18next-http-middleware with full Chinese analysis, references, and POCs where available.