URL Injection and Server-Side Request Forgery in i18next-http-backend by i18next
CVE-2026-105800
3.7LOW
What is CVE-2026-105800?
The i18next-http-backend prior to version 4.0.2 contains a vulnerability that allows attacker-controlled language or namespace values to be interpolated into a custom loadPath or addPath. If these values begin with {{lng}} or {{ns}}, they can manipulate colon-based inputs into absolute URLs, or, in browser contexts, create protocol-relative URLs from double-slash namespaces. This manipulation risks unintended data exposure and server-side request forgery by redirecting requests away from their intended origins. Notably, the default template /locales/{{lng}}/{{ns}}.json remains safe against this threat. This vulnerability has been resolved in the 4.0.2 release.
Affected Version(s)
i18next-http-backend < 4.0.2
