Vulnerabilities > CVE-2025-2691 - Unspecified vulnerability in Nossrf Project Nossrf
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |