CVE-2025-59436: Fedorindutny IP

Low severity, CVSS 3.2. EPSS: 0.1% chance of exploitation in the next 30 days.

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2024-29415.

Affected products

Published 2025-09-16. Last modified 2026-06-17.