chore(deps): update dependency vnu-jar to v26 [security]#205
Open
renovate-rancher[bot] wants to merge 1 commit intomainfrom
Open
chore(deps): update dependency vnu-jar to v26 [security]#205renovate-rancher[bot] wants to merge 1 commit intomainfrom
renovate-rancher[bot] wants to merge 1 commit intomainfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
23.4.11→26.2.1Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability
CVE-2025-15104 / GHSA-fccg-7w3p-w66f
More information
Details
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:PReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
validator/validator (vnu-jar)
v26.2.1Compare Source
v26.1.11Compare Source
v26.1.9Compare Source
v26.1.7Compare Source
v26.1.5Compare Source
v26.1.4Compare Source
v26.1.3Compare Source
v26.1.2Compare Source
v26.1.1Compare Source
v25.12.31Compare Source
v25.12.30Compare Source
v25.12.29Compare Source
v25.12.28Compare Source
v25.12.27Compare Source
v25.12.26Compare Source
v25.12.25Compare Source
v25.12.24Compare Source
v25.12.23Compare Source
v25.12.22Compare Source
v25.12.21Compare Source
v25.12.20Compare Source
v25.12.19Compare Source
v25.12.18Compare Source
v25.12.17Compare Source
v25.12.16Compare Source
v25.12.15Compare Source
v25.12.14Compare Source
v25.12.13Compare Source
v25.12.12Compare Source
v25.12.11Compare Source
v25.12.9Compare Source
v25.12.8Compare Source
v25.12.7Compare Source
v25.12.6Compare Source
v25.12.5Compare Source
v25.12.2Compare Source
v25.12.1Compare Source
v25.11.30Compare Source
v25.11.29Compare Source
v25.11.28Compare Source
v25.11.27Compare Source
v25.11.25Compare Source
v25.11.20Compare Source
v25.11.19Compare Source
v25.11.17Compare Source
v25.11.8Compare Source
v25.11.7Compare Source
v25.11.6Compare Source
v25.11.5Compare Source
v25.11.4Compare Source
v25.11.3Compare Source
v25.11.2Compare Source
v25.11.1Compare Source
v24.10.17Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.