
🚨High - 9Router DNS-Rebinding SSRF in Image Fetch (CVE-2026-56676) 9Router validates image URLs by resolving the host before fetching, but its server-side image fetch (image.js) does a separate DNS resolution later. That TOCTOU gap enables DNS rebinding: an authenticated proxy user with a vision-capable model supplies an attacker-controlled DNS name that first resolves to a public IP (passing the check), then rebinds to an internal address at fetch time. The result is server-side requests to internal-only HTTP services (SSRF) despite the URL validation. It's the classic check-then-use DNS rebinding pattern. 👉Upgrade 9Router to 0.5.2.
Post summary
CVE-2026-56676 exploits a TOCTOU DNS rebinding flaw in 9Router’s image fetch, enabling SSRF. Upgrading to version 0.5.2 resolves the vulnerability.


