CVE-2026-27730
Last modified
CVE-2026-27730 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. The service tries to block localhost/internal targets, but the validation is based on hostname string checks and can be bypassed using DNS alias domains. This allows an external requester to make the esm.sh server fetch internal localhost services. As of time of publication, no known patched versions exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Esm | Esm.Sh | <= 137 |
References
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-p2v6-84h2-5x4rExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-27730?
How severe is CVE-2026-27730?
How do I fix CVE-2026-27730?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2772Use-after-free in the Audio/Video: Playback component. This …9.8
- CVE-2026-27723OpenProject is an open-source, web-based project management …5.3
- CVE-2026-27727mchange-commons-java, a library that provides Java utilities…9.8
- CVE-2026-27728OneUptime is a solution for monitoring and managing online s…8.8
- CVE-2026-27729Astro is a web framework. In versions 9.0.0 through 9.5.3, A…7.5
- CVE-2026-2773Incorrect boundary conditions in the Web Audio component. Th…9.8
- CVE-2026-27732WWBN AVideo is an open source video platform. Prior to versi…8.1
- CVE-2026-27734Beszel is a server monitoring platform. Prior to version 0.1…6.5
- CVE-2026-27735Model Context Protocol Servers is a collection of reference …6.5
- CVE-2026-27736BigBlueButton is an open-source virtual classroom. In versio…6.1
- CVE-2026-27737BigBlueButton is an open-source virtual classroom. In versio…6.5
- CVE-2026-27738The Angular SSR is a server-rise rendering tool for Angular …6.9
Are you affected by CVE-2026-27730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
