{"id":"CVE-2026-103530","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-103530","summary":"A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint.…","details":"A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.","published":"2026-10-01T00:16:43.287","modified":"2026-10-01T00:16:44.563","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/decolua/9router/pull/3723","label":"decolua/9router#3723"},"references":[{"type":"WEB","url":"https://github.com/decolua/9router/"},{"type":"WEB","url":"https://github.com/decolua/9router/issues/3714"},{"type":"WEB","url":"https://github.com/decolua/9router/pull/3723"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-103530"},{"type":"WEB","url":"https://vuldb.com/submit/956865"},{"type":"WEB","url":"https://vuldb.com/vuln/412342"},{"type":"WEB","url":"https://vuldb.com/vuln/412342/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-01T00:16:44.563"}}