
CVE-2026-27730 http://esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in http://esm.sh’s `/http(s)` … https://www.cve.org/CVERecord?id=CVE-2026-27730
Post summary
The post announces that CVE‑2026‑27730 is an SSRF vulnerability in esm.sh CDN affecting versions up to 137.

