{"id":"CVE-2026-105800","summary":"i18next-http-backend incomplete URL validation permits SSRF","details":"i18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that begins directly with {{lng}} or {{ns}} can make colon-based input become an absolute URL or, in browsers, make a double-slash namespace become a protocol-relative URL. The resulting request can leave the intended origin and cause URL injection or server-side request forgery. The default /locales/{{lng}}/{{ns}}.json template and templates with a leading path or origin are not affected because the placeholder does not occupy the URL's structural beginning. This issue is fixed in version 4.0.2.","aliases":["GHSA-xvq9-wjp8-hwqf"],"modified":"2026-10-07T02:47:26.632261660Z","published":"2026-10-06T14:48:05.267Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-74","CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105800.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105800.json"},{"type":"FIX","url":"https://github.com/i18next/i18next-http-backend/commit/07e028862b25d0b9251bf3cafb92be2d35285f85"},{"type":"WEB","url":"https://github.com/i18next/i18next-http-backend/releases/tag/v4.0.2"},{"type":"ADVISORY","url":"https://github.com/i18next/i18next-http-backend/security/advisories/GHSA-xvq9-wjp8-hwqf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105800"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/i18next/i18next-http-backend","events":[{"introduced":"0"},{"fixed":"7db2f606dfd720d69ad54ff896bd6e7236d9d15e"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.0.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v4.0.1","v4.0.0","v3.0.6","v3.0.5","v3.0.4","v3.0.2","v2.6.2","v3.0.1","v3.0.0","v2.7.0","v2.6.1","v2.6.0","v2.5.2","v2.5.1","v2.5.0","v2.4.3","v2.4.2","v2.4.1","v2.4.0","v2.3.1","v2.3.0","v2.2.2","v2.2.1","v2.2.0","v2.1.1","v2.1.0","v2.0.2","v2.0.1","v2.0.0","v1.4.5","v1.4.4","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.2","v1.3.1","v1.3.0","v1.2.8","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.24","v1.0.23","v1.0.22","v1.0.21","v1.0.20","v1.0.19","v1.0.18","v1.0.17","v1.0.16","v1.0.15","v1.0.14","v1.0.13","v1.0.12","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105800.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}