212 packages matching “rebinding”
host-validation-middleware
v0.1.4 · 4 months ago
Middleware for validating host headers in requests to protect against DNS rebinding attacks.
No known vulnerabilities
host-validation
v2.0.1 · 7 years ago
Node.js middleware to validate Host and Referer headers in HTTP requests and protect against DNS rebinding attacks.
No known vulnerabilities
@getpipher/welcome
v0.1.8 · 24 days ago
Stunning, dismissible home-page overlay for the pi coding agent — branded splash at startup, then 100% native pi. No native hotkey rebinding.
No known vulnerabilities
svelte-keybinds
v1.0.9 · 1 year ago
Minimalistic keybinds interface, with rebinding and saving. Made for Svelte.
No known vulnerabilities
server-fetch
v1.0.10 · 3 months ago
SSRF-safe fetch() for server-side use — validates IPs, enforces scheme/port, eliminates DNS rebinding via undici connect.lookup
No known vulnerabilities
whonow
v1.2.0 · 8 years ago
A malicious DNS server for executing DNS Rebinding attacks on the fly.
No known vulnerabilities
ssrf-fetch
v0.1.0 · 1 month ago
A drop-in fetch() that blocks SSRF: refuses loopback/private/link-local/CGNAT targets and pins the connection to the validated IP to defeat DNS rebinding (TOCTOU).
No known vulnerabilities
fumadocs-dgmo
v0.8.6 · 1 day ago
Fumadocs integration to render DGMO diagrams from fenced code blocks at build time. Two-step install: `withDgmo()` in source.config.ts plus `<DgmoClient />` in app/layout.tsx — the client component handles route-change rebinding and auto-imports the theme
No known vulnerabilities
ssrf-agent-guard
v0.1.14 · 6 months ago
A TypeScript SSRF protection library for Node.js (express/axios) with advanced policies, DNS rebinding detection and cloud metadata protection.
No known vulnerabilities
@modelcontextprotocol/express
v2.0.0 · 23 days ago
Express adapters for the Model Context Protocol TypeScript server SDK - Express middleware
No known vulnerabilities
nextra-dgmo
v0.4.6 · 1 day ago
Nextra integration to render DGMO diagrams from fenced code blocks at build time. Two-step install: `withDgmo()` in next.config.mjs plus `<DgmoClient />` in app/layout.tsx — the client component handles route-change rebinding and auto-imports the theme-aw
No known vulnerabilities
@ariada-org/url-guard
v0.1.0 · 26 days ago
Shared SSRF guard — reject non-http(s) schemes and resolve+validate hostnames against loopback/private/link-local/reserved ranges, returning a pinned IP so callers can close DNS-rebinding. Open source under EUPL-1.2.
No known vulnerabilities
safe-fetch-mcp-server
v0.1.3 · 8 days ago
A secure-by-default MCP server for fetching web content: SSRF, DNS-rebinding, and redirect-to-internal protection with post-resolution IP validation.
No known vulnerabilities
@modelcontextprotocol/fastify
v2.0.0 · 23 days ago
Fastify adapters for the Model Context Protocol TypeScript server SDK - Fastify middleware
No known vulnerabilities
@streetjs/webhook-dispatcher
v1.0.0 · 1 month ago
StreetJS outbound webhook dispatcher: an SSRF-hardened, HTTPS-only delivery queue with HMAC-SHA256 signatures, bounded queue + concurrency, exponential-backoff retries, DNS-rebinding protection, and private-CA TLS. Zero runtime dependencies. (Distinct fro
No known vulnerabilities
@deepseek-ai/dsh-client-connection
v0.0.1-rc.1 · 9 days ago
Wire consumer layer: HTTP-up/WebSocket-down client, ConnectionController dual streams with reconnect, and fixture api
No known vulnerabilities
@a2a-compliance/core
v0.3.3 · 3 months ago
Library for probing, validating, and reporting on A2A (Agent2Agent) protocol endpoints. Assertion engine + reporters (JSON, JUnit, SARIF 2.1.0, badge SVG, snapshot diff), SSRF guard, DNS-rebinding pin, check catalog. Used by @a2a-compliance/cli.
No known vulnerabilities
@kontourai/forage
v0.5.1 · 18 days ago
Safe, replayable web crawling for review pipelines — a crawler for untrusted URLs.
No known vulnerabilities
@inklu/keys
v1.3.0 · 1 day ago
A command system for the web — typed commands, portable keybindings, scopes, sequences, conflict detection, rebinding, and platform-aware display.
No known vulnerabilities
@tigerdata/mcp-boilerplate
v1.6.3 · 26 days ago
MCP boilerplate code for Node.js
No known vulnerabilities