2.9
CVSSv3

CVE-2024-28607

CVSSv4: NA | CVSSv3: 2.9 | CVSSv2: NA | VMScore: 390 | EPSS: 0.00016 | KEV: Not Included
Published: 11/03/2025 Updated: 11/03/2025

Vulnerability Summary

Server-Side Request Forgery in Node.js ip-utils Package Through 2.4.0

The ip-utils package for Node.js through version 2.4.0 contains a potential server-side request forgery (SSRF) vulnerability. The issue stems from incorrect IP address categorization, where certain IP addresses like 0x7f.1 are incorrectly identified as globally routable due to a falsy return value from the isPrivate method. This misclassification could potentially allow an attacker to bypass IP address restrictions and make unauthorized requests.

Vulnerable Product Search on Vulmon Subscribe to Product

librasean ip-utils