@apidevtools/json-schema-ref-parser is vulnerable to Server-Side Request Forgery (SSRF)
54
Medium Risk
The HTTP resolver fetches externally influenced $ref URLs and, when the safe-URL option is enabled, validates them with a string-only check that inspects the literal hostname. A hostname that passes validation can resolve to a private address, allowing DNS rebinding to reach internal network resources. Cross-origin redirects also resend the configured Authorization, Cookie, and proxy headers, exposing credentials to unintended hosts. The fix resolves and pins validated addresses, fails closed on unsafe resolution, and strips sensitive headers on cross-origin redirects.
You are affected if you are using a version that falls within the vulnerable range and you resolve externally influenced $ref URLs over HTTP while relying on the safeUrlResolver option or sending authenticated requests.
@apidevtools/json-schema-ref-parser is vulnerable to Server-Side Request Forgery (SSRF) in versions 14.0.0 - 15.5.0.
Upgrade the @apidevtools/json-schema-ref-parser library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant