CVE-2023-42282: Fedorindutny IP

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Affected products

  • Fedorindutny IP: before 1.1.9 (fixed in 1.1.9); version 2.0.0 only

Published 2024-02-08. Last modified 2026-06-17.