ssrfcheck
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ssrfcheckpage 1 of 1
- CVE-2025-8267HIGHCVSS 8.2EG 8.2✓ Fixed in 1.2.02025-07-28
Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (…
- CVE-2026-43929HIGHCVSS 8.2EG 8.22026-05-12
ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 addres…
Check whether ssrfcheck is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ssrfcheck CVEs against the assets you own.
Start Free Scan →