{"id":"CVE-2025-50180","aliases":["GHSA-3c9r-837r-qqm4","GO-2026-4545"],"url":"https://o3.security/vulnerability/CVE-2025-50180","summary":"esm.sh is vulnerable to full-response SSRF","details":"esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.","published":"2026-02-25T15:32:56.449Z","modified":"2026-09-19T11:45:13.844970633Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/esm-dev/esm.sh","fixedVersion":"0.0.0-20250616164159-0593516c4cfa"}],"fix":{"url":"https://github.com/esm-dev/esm.sh/commit/0593516c4cfab49ad3b4900416a8432ff2e23eb0","label":"esm-dev/esm.sh@0593516"},"references":[{"type":"WEB","url":"https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/internal/fetch/fetch.go#L13"},{"type":"WEB","url":"https://github.com/esm-dev/esm.sh/blob/f80ff8c8d58749e77fa964abde468fc61f8bd89e/server/router.go#L511"},{"type":"WEB","url":"https://github.com/esm-dev/esm.sh/releases/tag/v137"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/50xxx/CVE-2025-50180.json"},{"type":"ADVISORY","url":"https://github.com/esm-dev/esm.sh/security/advisories/GHSA-3c9r-837r-qqm4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50180"},{"type":"FIX","url":"https://github.com/esm-dev/esm.sh/commit/0593516c4cfab49ad3b4900416a8432ff2e23eb0"},{"type":"FIX","url":"https://github.com/esm-dev/esm.sh/pull/1149"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-19T11:45:13.844970633Z"}}