CVE-2025-15104
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd).
Published:Jan 16, 2026
Last Modified:Jan 23, 2026
EPS:Jan 16, 2026
EPSS Score:0.00083
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
The Nu Html Checker
Product
The Nu Html Checker
The Nu Html Checker
The Nu Html Checker
Vendor
Validator
Product
Validator
Validator
Validator
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
