PatchSiren

HackingRepo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH HackingRepo CVE published 2026-05-12

CVE-2026-44232

CVE-2026-44232 is a high-severity SSRF defense bypass in the Node.js library dssrf-js. According to the public advisory, versions before 1.3.0 allow every IPv6 category to bypass the is_url_safe check. The issue is fixed in 1.3.0. The NVD record lists the vulnerability as Deferred and references the GitHub security advisory.