Skip to content

[VULN] Security Alert for validator #814

@my-local-testing-github-app

Description

@my-local-testing-github-app

Alert IDs:

  • 88f1e1f1-8b33-4fb9-b89a-87145e3e4d02

Vulnerabilities in validator

Release: March19 release 2

Total Vulnerabilities: 1


1. CVE-2025-15104

Severity: MEDIUM (Score: 5.3)

Description:
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).

Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-15104

Alert ID: 88f1e1f1-8b33-4fb9-b89a-87145e3e4d02


Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions