The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ip(npm) | 2.0.0 | 2.0.1 | N/A |
| ip(npm) | 0 | 1.1.9 | N/A |
CVSS Metrics