Executive brief
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route in github.com/esm-dev/esm.sh
Affected products
- Go github.com/esm-dev/esm.sh
Junglewise Threat Intelligence
CVE-2026-27730 · Severity: low · CVSS 3 · Published 2026-02-27
Technologies: github.com/esm-dev/esm.sh (Go). Vendors: Go.
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route in github.com/esm-dev/esm.sh