Vulnerability Report: GO-2026-4554
- CVE-2026-27730, GHSA-p2v6-84h2-5x4r
- Affects: github.com/esm-dev/esm.sh
- Published: Feb 27, 2026
- Unreviewed
esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route in github.com/esm-dev/esm.sh
For detailed information about this vulnerability, visit https://github.com/esm-dev/esm.sh/security/advisories/GHSA-p2v6-84h2-5x4r or https://nvd.nist.gov/vuln/detail/CVE-2026-27730.
Affected Modules
-
PathGo Versions
-
before v0.0.0-20250616164159-0593516c4cfa
Aliases
References
- https://github.com/esm-dev/esm.sh/security/advisories/GHSA-p2v6-84h2-5x4r
- https://nvd.nist.gov/vuln/detail/CVE-2026-27730
- https://github.com/esm-dev/esm.sh/commit/0593516c4cfab49ad3b4900416a8432ff2e23eb0
- https://github.com/esm-dev/esm.sh/pull/1149
- https://github.com/esm-dev/esm.sh/releases/tag/v137
- https://vuln.go.dev/ID/GO-2026-4554.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.