๐Ÿ” CVE Alert

CVE-2026-61704

HIGH 7.5

link-preview-js DNS Rebinding SSRF Bypass / Incomplete Fix for CVE-2026-43897

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback or internal address during the final connection. This DNS rebinding condition bypasses the SSRF protection and can cause the server-side preview fetch to reach internal HTTP resources. Redirect handling is affected by the same validation-to-fetch mismatch. This issue is fixed in version 4.0.4.

CWE CWE-918
Vendor op-engineering
Product link-preview-js
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for op-engineering link-preview-js

Be the first to know when new high vulnerabilities affecting op-engineering link-preview-js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

OP-Engineering / link-preview-js
< 4.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-cpjf-6666-r8fx github.com: https://github.com/OP-Engineering/link-preview-js/pull/181 github.com: https://github.com/OP-Engineering/link-preview-js/commit/6ee25043dd60b097eb70b4ce049aac94b28239e3 github.com: https://github.com/OP-Engineering/link-preview-js/commit/f3a3dd84adbb9d32d06a933f44ff3eaa837f9a12 github.com: https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.4