HomeDefault status
affected
7c1de6db76749ceb7b382493da29c4348853cf6b (git)
unaffected
Description
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
7c1de6db76749ceb7b382493da29c4348853cf6b (git)
Credits
ksw9722 / Kim Si Ung
References
cve.naver.com/detail/cve-2026-23768.html
github.com/naver/lucy-xss-filter/pull/31