Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librechat
Librechat librechat |
|
| CPEs | cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:* cpe:2.3:a:librechat:librechat:0.8.3:rc1:*:*:*:*:*:* cpe:2.3:a:librechat:librechat:0.8.3:rc2:*:*:*:*:*:* |
|
| Vendors & Products |
Librechat
Librechat librechat |
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danny-avila
Danny-avila libre Chat |
|
| Vendors & Products |
Danny-avila
Danny-avila libre Chat |
Fri, 27 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP requests to internal network resources — including cloud metadata services (e.g., AWS `169.254.169.254`), loopback, and RFC1918 ranges. Version 0.8.3 fixes the issue. | |
| Title | LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T19:10:14.342Z
Reserved: 2026-03-10T15:10:10.656Z
Link: CVE-2026-31943
Updated: 2026-03-31T19:08:23.278Z
Status : Modified
Published: 2026-03-27T20:16:29.897
Modified: 2026-03-31T20:16:27.063
Link: CVE-2026-31943
No data.
OpenCVE Enrichment
Updated: 2026-03-31T20:00:52Z