Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-42353

HIGH NVD
CVSS Score 8.2
Severity HIGH
Published May 08, 2026
Vendor unknown

Description

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, โ€ฆ) without any sanitization. Depending on which backend is configured, the unvalidated path segments enable either path traversal or SSRF. This issue has been patched in version 3.9.3.

References