Vulnerabilities > Fedorindutny

DATE CVE VULNERABILITY TITLE RISK
2024-02-08 CVE-2023-42282 Server-Side Request Forgery (SSRF) vulnerability in Fedorindutny IP
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
network
low complexity
fedorindutny CWE-918
critical
9.8