CVE-2026-61704
link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4.
| CWE | CWE-918 |
| Vendor | op-engineering |
| Product | link-preview-js |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for op-engineering link-preview-js
Be the first to know when new high vulnerabilities affecting op-engineering link-preview-js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
OP-Engineering / link-preview-js
< 4.0.4
References
github.com: https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-cpjf-6666-r8fx github.com: https://github.com/OP-Engineering/link-preview-js/pull/181 github.com: https://github.com/OP-Engineering/link-preview-js/commit/6ee25043dd60b097eb70b4ce049aac94b28239e3 github.com: https://github.com/OP-Engineering/link-preview-js/commit/f3a3dd84adbb9d32d06a933f44ff3eaa837f9a12 github.com: https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.4