/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2023-42282

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-42282

Severity

9.8

Critical

CVSS V3

Description

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing