{"id":"CVE-2026-103530","summary":"decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery","details":"A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.","modified":"2026-10-03T03:30:58.652713531Z","published":"2026-09-30T23:45:11.762Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103530.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.5.0"},{"last_affected":"0.5.0"},{"introduced":"0.5.1"},{"last_affected":"0.5.1"},{"introduced":"0.5.3"},{"last_affected":"0.5.3"},{"introduced":"0.5.5"},{"last_affected":"0.5.5"},{"introduced":"0.5.7"},{"last_affected":"0.5.7"},{"introduced":"0.5.10"},{"last_affected":"0.5.10"},{"introduced":"0.5.11"},{"last_affected":"0.5.11"},{"introduced":"0.5.13"},{"last_affected":"0.5.13"},{"introduced":"0.5.14"},{"last_affected":"0.5.14"},{"introduced":"0.5.16"},{"last_affected":"0.5.16"},{"introduced":"0.5.17"},{"last_affected":"0.5.17"},{"introduced":"0.5.19"},{"last_affected":"0.5.19"},{"introduced":"0.5.21"},{"last_affected":"0.5.21"},{"introduced":"0.5.22"},{"last_affected":"0.5.22"},{"introduced":"0.5.23"},{"last_affected":"0.5.23"},{"introduced":"0.5.24"},{"last_affected":"0.5.24"},{"introduced":"0.5.25"},{"last_affected":"0.5.25"},{"introduced":"0.5.26"},{"last_affected":"0.5.26"},{"introduced":"0.5.27"},{"last_affected":"0.5.27"},{"introduced":"0.5.28"},{"last_affected":"0.5.28"},{"introduced":"0.5.29"},{"last_affected":"0.5.29"},{"introduced":"0.5.31"},{"last_affected":"0.5.31"},{"introduced":"0.5.32"},{"last_affected":"0.5.32"},{"introduced":"0.5.33"},{"last_affected":"0.5.33"},{"introduced":"0.5.34"},{"last_affected":"0.5.34"},{"introduced":"0.5.36"},{"last_affected":"0.5.36"},{"introduced":"0.5.37"},{"last_affected":"0.5.37"},{"introduced":"0.5.38"},{"last_affected":"0.5.38"},{"introduced":"0.5.39"},{"last_affected":"0.5.39"},{"introduced":"0.5.41"},{"last_affected":"0.5.41"},{"introduced":"0.5.42"},{"last_affected":"0.5.42"},{"introduced":"0.5.43"},{"last_affected":"0.5.43"},{"introduced":"0.5.44"},{"last_affected":"0.5.44"},{"introduced":"0.5.46"},{"last_affected":"0.5.46"},{"introduced":"0.5.47"},{"last_affected":"0.5.47"},{"introduced":"0.5.48"},{"last_affected":"0.5.48"},{"introduced":"0.5.49"},{"last_affected":"0.5.49"},{"introduced":"0.5.51"},{"last_affected":"0.5.51"},{"introduced":"0.5.52"},{"last_affected":"0.5.52"},{"introduced":"0.5.53"},{"last_affected":"0.5.53"},{"introduced":"0.5.54"},{"last_affected":"0.5.54"}]}]},"references":[{"type":"WEB","url":"https://github.com/decolua/9router/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103530.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103530"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-103530"},{"type":"ADVISORY","url":"https://vuldb.com/submit/956865"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/412342"},{"type":"REPORT","url":"https://github.com/decolua/9router/issues/3714"},{"type":"REPORT","url":"https://vuldb.com/vuln/412342/cti"},{"type":"FIX","url":"https://github.com/decolua/9router/pull/3723"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/decolua/9router","events":[{"introduced":"5da508af3c3dc6e920286141d1a4ddcd4ec245db"},{"last_affected":"699edac3273e13d4744bc46f6082618f08560702"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.5.2"},{"last_affected":"0.5.2"},{"introduced":"0.5.4"},{"last_affected":"0.5.4"},{"introduced":"0.5.6"},{"last_affected":"0.5.6"},{"introduced":"0.5.8"},{"last_affected":"0.5.8"},{"introduced":"0.5.9"},{"last_affected":"0.5.9"},{"introduced":"0.5.12"},{"last_affected":"0.5.12"},{"introduced":"0.5.15"},{"last_affected":"0.5.15"},{"introduced":"0.5.18"},{"last_affected":"0.5.18"},{"introduced":"0.5.20"},{"last_affected":"0.5.20"},{"introduced":"0.5.30"},{"last_affected":"0.5.30"},{"introduced":"0.5.35"},{"last_affected":"0.5.35"},{"introduced":"0.5.40"},{"last_affected":"0.5.40"},{"introduced":"0.5.45"},{"last_affected":"0.5.45"},{"introduced":"0.5.50"},{"last_affected":"0.5.50"},{"introduced":"0.5.55"},{"last_affected":"0.5.55"}]}}],"versions":["0.5.12","0.5.15","0.5.18","0.5.2","0.5.20","0.5.30","0.5.35","0.5.4","0.5.40","0.5.45","0.5.50","0.5.55","0.5.6","0.5.8","0.5.9","v0.5.55","v0.5.50","v0.5.45","v0.5.40","v0.5.35","v0.5.18","v0.5.15","v0.5.12","v0.5.8","v0.5.6","v0.5.4","v0.5.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103530.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}