CVE-2023-42282

CRITICAL9.8EPSS 0.67%

NPM IP package incorrectly identifies some private IP addresses as public

Published: 2/8/2024Modified: 4/28/2026

Description

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (9)