{"id":"CVE-2026-43897","aliases":["GHSA-4gp8-rjrq-ch6q"],"url":"https://o3.security/vulnerability/CVE-2026-43897","summary":"Link Preview JS: vunerable to IPv6 and internal loopback attacks","details":"Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks. This vulnerability is fixed in 4.0.1.","published":"2026-05-11T21:14:40.495Z","modified":"2026-08-07T11:49:58.050366539Z","cvss":null,"epss":{"score":0.00432,"percentile":0.35627,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"link-preview-js","fixedVersion":"4.0.1"}],"fix":{"url":"https://github.com/OP-Engineering/link-preview-js/commit/4396d48909fab37553c0e93e26447fe218363ede","label":"OP-Engineering/link-preview-js@4396d48"},"references":[{"type":"WEB","url":"https://github.com/OP-Engineering/link-preview-js/releases/tag/4.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43897.json"},{"type":"ADVISORY","url":"https://github.com/OP-Engineering/link-preview-js/security/advisories/GHSA-4gp8-rjrq-ch6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43897"},{"type":"FIX","url":"https://github.com/OP-Engineering/link-preview-js/commit/4396d48909fab37553c0e93e26447fe218363ede"},{"type":"FIX","url":"https://github.com/OP-Engineering/link-preview-js/pull/179"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:49:58.050366539Z"}}