CVE-2025-59436: Fedorindutny IP
Low severity, CVSS 3.2. EPSS: 0.1% chance of exploitation in the next 30 days.
The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.
Affected products
- Fedorindutny IP: up to and including 2.0.1
Published 2025-09-16. Last modified 2026-06-17.