CVE-2025-24354: Imgproxy

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.

Affected products

  • Imgproxy Imgproxy: before 3.27.2 (fixed in 3.27.2)

Published 2025-01-27. Last modified 2026-06-17.