URL Injection and Server-Side Request Forgery in i18next-http-backend by i18next
CVE-2026-105800

3.7LOW

Key Information:

Vendor

I18next

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105800?

The i18next-http-backend prior to version 4.0.2 contains a vulnerability that allows attacker-controlled language or namespace values to be interpolated into a custom loadPath or addPath. If these values begin with {{lng}} or {{ns}}, they can manipulate colon-based inputs into absolute URLs, or, in browser contexts, create protocol-relative URLs from double-slash namespaces. This manipulation risks unintended data exposure and server-side request forgery by redirecting requests away from their intended origins. Notably, the default template /locales/{{lng}}/{{ns}}.json remains safe against this threat. This vulnerability has been resolved in the 4.0.2 release.

Affected Version(s)

i18next-http-backend < 4.0.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.