CVE-2026-23768: SSRF
Published Jan 16, 2026
·Updated
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension.
Affected Software
2 affected components
npm/lucy-xss-filter<7c1de6d
NAVER Lucy-xss-filter<2025-06-08
Remediation
Patch Available
Event History
Jan 16, 2026
CVE Published
via MITRE·05:20 AM
Data Sourced
via MITRE·05:20 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 3, 58101
Event
via FIRST·12:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-23768?
CVE-2026-23768 is considered a medium severity vulnerability.
2
How do I fix CVE-2026-23768?
To fix CVE-2026-23768, update the lucy-xss-filter to a version above 7c1de6d.
3
What types of attacks does CVE-2026-23768 allow?
CVE-2026-23768 allows attackers to induce server-side HEAD requests to arbitrary URLs.
4
Which options need to be enabled for CVE-2026-23768 to be exploitable?
For CVE-2026-23768 to be exploitable, the ObjectSecurityListener or EmbedSecurityListener options must be enabled.
5
What specific tags are involved in the CVE-2026-23768 vulnerability?
CVE-2026-23768 involves the use of embed or object tags with a src attribute that is missing a file extension.