CVE-2026-76898 | JGraph draw.io up to 30.3.7 IPv6 Address Validation Utils.java Utils.sanitizeUrl dns rebinding

SecurityVulns

A vulnerability classified as critical has been found in JGraph draw.io up to 30.3.7. This vulnerability affects the function Utils.sanitizeUrl of the file src/main/java/com/mxgraph/online/Utils.java of the component IPv6 Address Validation. This manipulation causes reliance on reverse dns resolution.

The identification of this vulnerability is CVE-2026-76898. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More