CVE-2025-9960: Is-Localhost-IP

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A restriction bypass vulnerability in is-localhost-ip could allow attackers to perform Server-Side Request Forgery (SSRF). This issue affects is-localhost-ip: 2.0.0.

Affected products

Published 2025-09-22. Last modified 2026-06-17.