CVE-2024-29415

HIGH8.1EPSS 84.3%

ip SSRF improper categorization in isPublic

Published: 6/2/2024Modified: 2/4/2026
Also known as:GHSA-2p57-rm9w-gvfpCGA-7qqv-69xq-jqc2

Description

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References (7)