Junglewise Threat Intelligence

CVE-2026-56676: decolua 9router SSRF via DNS rebinding in image prefetch

CVE-2026-56676 · Severity: high · CVSS 7.4 · Published 2026-07-10

Technologies: Decolua 9router. Vendors: npm.

Executive brief

9Router is an AI routing tool used to manage and optimize requests to various Large Language Models. A security flaw allows authenticated users to bypass network protections and force the router to send requests to internal company servers or private cloud services. This could lead to the exposure of sensitive internal data, unauthorized access to administrative panels, or disruption of internal operations.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in 9Router due to a Time-of-Check Time-of-Use (TOCTOU) flaw in how image URLs are validated. The component 'open-sse/translator/concerns/image.js' resolves a hostname to verify it is a public IP, but then performs a second, independent DNS resolution when actually fetching the image. An attacker can use a DNS rebinding attack—where the first resolution returns a public IP and the second returns a private/internal IP—to bypass the 'public-host' guard. This allows an authenticated attacker using a vision-capable model to make requests to internal Docker services, cloud metadata endpoints, or private administrative interfaces. The issue is fixed in version 0.5.2 by pinning the resolved IP address.

Affected products

  • decolua 9router < 0.5.2

Timeline

  • 2026-06-17: patched: Version 0.5.2 released
  • 2026-07-07: advisory: GitHub Security Advisory published
  • 2026-07-10: disclosed: CVE published to NVD

References

Related threats