Junglewise Threat Intelligence

CVE-2025-15104: Nu Html Checker SSRF via DNS rebinding bypass

CVE-2025-15104 · Severity: medium · CVSS 4 · Published 2026-01-16

Vendors: Maven, npm.

Executive brief

Nu Html Checker (validator.nu) is an HTML validation service used by developers to check web pages for correctness. The service contains a server-side request forgery vulnerability that allows attackers to bypass hostname protections and make the server request internal resources, such as localhost services. This could expose sensitive internal services or configuration information that should not be accessible from the internet.

Technical details

Nu Html Checker contains a server-side request forgery (SSRF) vulnerability (CWE-918) that allows remote attackers to bypass hostname-based access controls intended to block requests to localhost and 127.0.0.1. The vulnerability can be exploited via DNS rebinding techniques or domains resolving to loopback addresses, enabling requests to internal resources without authentication. An attacker can make arbitrary HTTP/HTTPS requests to services running on the validator server or internal network. The vulnerability affects all versions up to and including 26.1.11, with patches status unknown.

Affected products

  • W3C Nu Html Checker up to 26.1.11

Timeline

  • 2026-01-16: disclosed

References