Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| nossrf(npm) | 0 | 1.0.4 | N/A |
CVSS Metrics