Skip to main content

CVE-2026-105800: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in i18next i18next-http-backend

0
Low
Published: 10/06/2026 (10/06/2026, 15:33:33 UTC)
Source: CVE Database V5
Vendor/Project: i18next
Product: i18next-http-backend

Description

There is an SSRF vulnerability when using `i18next-http-backend`. A colon in an attacker-controlled language value can make a custom path template request an unintended origin. This is reachable under the following conditions: Attacker controls i18next language or namespace input that is interpolated into loadPath. ## Proof of Concept ```js // SSRF through a colon-only URL scheme in i18next-http-backend interpolation. const http = require("node:http"); const Backend = require("i18next-http-backend"); function read(backend, lng, ns) { return new Promise((resolve) => { backend.read(lng, ns, (err) => resolve(err)); }); } async function main() { let gotRequest = false; const server = http.createServer((req, res) => { gotRequest = req.url === "/common.json"; res.writeHead(200, { "content-type": "application/json" }); res.end("{}"); }); await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve)); const backend = new Backend(null, { loadPath: "{{lng}}/{{ns}}.json" }); const lng = `http:127.0.0.1:${server.address().port}`; const err = await read(backend, lng, "common"); server.close(); const vulnerable = gotRequest && !err; console.log(vulnerable ? "VULNERABLE" : "SAFE"); if (!vulnerable) process.exitCode = 1; } main(); ``` Run: ```bash npm install --ignore-scripts node poc.js ``` The expected result is: ```text VULNERABLE ``` ## Why the Previous Patch Was Incomplete This vulnerability is caused by an incomplete patch for [CVE-2026-41691](https://github.com/advisories/GHSA-q89c-q3h5-w34g). The previous patch addressed the following behavior: Original hardening blocks path traversal and selected URL-control characters in lng/ns. The following bypass remains in the current release: lng=http:127.0.0.1:<port> with loadPath={{lng}}/{{ns}}.json; colon is not blocked and produces an outbound request. ## Impact The attacker-controlled language or namespace value can redirect the backend request to an unintended origin, resulting in URL injection and possible SSRF. ## Recommended Fix Parse the final URL and require it to remain within the intended origin and path. If absolute URLs are supported, validate them against an explicit allowlist. Please let us know if you need any additional information or clarification. We are happy to prepare a pull request if that would be helpful. Thank you for reviewing this report. ## Maintainer note Confirmed and fixed in 4.0.2 (commit i18next/i18next-http-backend@07e0288). **Preconditions.** The bypass only works when the `loadPath` / `addPath` template *begins* directly with `{{lng}}` or `{{ns}}` — no origin and no leading `/`, e.g. `{{lng}}/{{ns}}.json`. Only in that position is `http:` parsed as a URL scheme. The default `/locales/{{lng}}/{{ns}}.json` and every template with a leading path or origin are **not** affected: a colon inside a path segment has no structural meaning there, and the resulting string is rejected as an invalid URL. The same template shape also allowed an `ns` value such as `//evil.example/x` to become a protocol-relative URL in browsers. **Fix.** `:` is now rejected in both `lng` and `ns` values, and `//` in `ns` values. No BCP-47 language code contains a colon, and `:` is i18next's default namespace separator, so no usable namespace name does either. **Affected range.** Versions before 3.0.5 had no validation at all and are reachable through this vector too, so the affected range is `< 4.0.2` rather than `>= 3.0.5, <= 4.0.1`.

CVSS v3.1

Score 3.7low

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected software

i18next

i18next-http-backend

Affected versions
<4.0.2
i18next-http-backend
pkg:npm/i18next-http-backend
Affected versions
<4.0.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 15:18:35 UTC

Technical Analysis

The vulnerability in i18next-http-backend (before 4.0.2) involves improper neutralization of special elements in output used by a downstream component, specifically in how language ({{lng}}) or namespace ({{ns}}) placeholders are handled when they appear at the very start of a custom loadPath or addPath URL template. If these placeholders are attacker-controlled, they can cause colon-based input to be interpreted as an absolute URL or, in browsers, a double-slash namespace to become a protocol-relative URL. This can lead to URL injection or server-side request forgery by making requests leave the intended origin. The default template /locales/{{lng}}/{{ns}}.json and templates with a leading path or origin are not vulnerable because the placeholder does not start the URL structure. The issue is resolved in version 4.0.2.

Potential Impact

An attacker can manipulate language or namespace values to cause the backend to request resources from unintended origins, potentially leading to server-side request forgery or URL injection. The impact is limited to information disclosure or redirection risks, with no direct integrity or availability impact. The CVSS score is 3.7 (low), reflecting the limited impact and the requirement for attacker control of input in specific URL template positions.

Mitigation Recommendations

Upgrade i18next-http-backend to version 4.0.2 or later where this vulnerability is fixed. Avoid using custom loadPath or addPath templates that begin directly with {{lng}} or {{ns}} placeholders. The default templates and those with leading paths or origins are not affected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-05T20:37:19.364Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac50de12cdf04f656bca32d

Added to database: 10/06/2026, 15:04:01 UTC

Last enriched: 10/06/2026, 15:18:35 UTC

Last updated: 10/06/2026, 21:42:15 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses