Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
Published Jan 16, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.47%
Description
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).
Affected products
-
- Version latest - commit:23f090a11bab8d0d4e698f1ffc197a4fe226a9cdStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Nu Html Checker | The Nu Html Checker | n/a |
|
No data.
No Red Hat product state for this CVE.
nu.validator:validator
Maven
Introduced 0 Fixed not fixedvnu-jar
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Maven | nu.validator:validator | 0 | not fixed |
| npm | vnu-jar | 0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:P
2 other sources (CVE.org, NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.47% (0.00472) | 38.57th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00425) | 33.70th | v5 (v2026.06.15) |
| Jan 17, 2026 | 0.06% (0.00063) | 19.99th | v4 (v2025.03.14) |
References (4)
- https://fluidattacks.com/advisories/europe exploitthird-party-advisoryThird Party Advisory
- https://github.com/advisories/GHSA-fccg-7w3p-w66f Advisory
- https://github.com/validator/validator product
- https://nvd.nist.gov/vuln/detail/CVE-2025-15104
| Link | Providers | Tags |
|---|---|---|
| https://fluidattacks.com/advisories/europe | exploitthird-party-advisoryThird Party Advisory | |
| https://github.com/advisories/GHSA-fccg-7w3p-w66f | Advisory | |
| https://github.com/validator/validator | product | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-15104 |
Change history (0)
No recorded changes yet.