CVE-2026-105800
Deferred Deferred - Pending Action

i18next-http-backend URL Injection via Language/Namespace

Vulnerability report for CVE-2026-105800, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

i18next-http-backend is a backend layer for i18next that loads translation resources in Node.js, browsers, and Deno. Prior to 4.0.2, attacker-controlled language or namespace values interpolated into a custom loadPath or addPath that begins directly with {{lng}} or {{ns}} can make colon-based input become an absolute URL or, in browsers, make a double-slash namespace become a protocol-relative URL. The resulting request can leave the intended origin and cause URL injection or server-side request forgery. The default /locales/{{lng}}/{{ns}}.json template and templates with a leading path or origin are not affected because the placeholder does not occupy the URL's structural beginning. This issue is fixed in version 4.0.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
i18next i18next-http-backend < 4.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects i18next-http-backend versions before 4.0.2. Attackers can manipulate language or namespace values to alter URLs, potentially causing requests to leave the intended origin. This may lead to URL injection or server-side request forgery. The issue occurs when custom loadPath or addPath templates start with placeholders like {{lng}} or {{ns}}.

Detection Guidance

Check if your system uses i18next-http-backend versions prior to 4.0.2 by inspecting package.json or running npm list i18next-http-backend. Look for custom loadPath or addPath templates starting with {{lng}} or {{ns}} that could allow URL injection.

Impact Analysis

An attacker could exploit this to make unintended requests to external servers, potentially accessing internal resources or sensitive data. In browsers, it might allow loading resources from untrusted origins. The impact depends on how the library is configured and used in applications.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements. Organizations using affected versions may face compliance risks if exploited.

Mitigation Strategies

Upgrade i18next-http-backend to version 4.0.2 or later. If upgrading is not possible, review and modify custom loadPath or addPath templates to avoid starting with {{lng}} or {{ns}} without additional path segments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105800. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart