CVE-2023-42282: Fedorindutny IP
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
Affected products
- Fedorindutny IP: before 1.1.9 (fixed in 1.1.9); version 2.0.0 only
Published 2024-02-08. Last modified 2026-06-17.