PT-2026-106757 · Npm · I18Next-Http-Backend

CVE-2026-105800

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions i18next-http-backend versions prior to 4.0.2
Description An issue exists where attacker-controlled language or namespace values interpolated into a custom loadPath or addPath can lead to URL injection or server-side request forgery (SSRF). This occurs when the path template begins directly with the {{lng}} or {{ns}} placeholders, allowing a colon-based input to be interpreted as an absolute URL or a double-slash namespace to become a protocol-relative URL in browsers. This allows the request to leave the intended origin and target an unintended destination. The default template /locales/{{lng}}/{{ns}}.json and templates with a leading path or origin are not affected.
Recommendations Update to version 4.0.2. As a temporary workaround, avoid using loadPath or addPath templates that begin directly with {{lng}} or {{ns}} placeholders.

Exploit

Fix

Special Elements Injection

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105800
GHSA-XVQ9-WJP8-HWQF

Affected Products

I18Next-Http-Backend