PatchSiren

OP-Engineering CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OP-Engineering CVE published 2026-08-20

CVE-2026-61704

CVE-2026-61704 is a high-severity vulnerability in Link Preview JS, a library used to extract web link information. The vulnerability, which has a CVSS score of 7.5, allows an attacker-controlled DNS server to bypass the SSRF protection and cause the server-side preview fetch to reach internal HTTP resources. This is achieved through a DNS rebinding condition, where the resolveDNSHost mitigation in index. [truncated]