Junglewise Threat Intelligence

CVE-2025-24354: GO-2025-3422 - imgproxy is vulnerable to SSRF against 0.0.0.0 in github.com/imgproxy/imgproxy

CVE-2025-24354 · Severity: low · CVSS 3.1 · Published 2025-01-28

Technologies: github.com/imgproxy/imgproxy/v3 (Go), github.com/imgproxy/imgproxy/v2 (Go), github.com/imgproxy/imgproxy (Go). Vendors: Go.

Executive brief

imgproxy is vulnerable to SSRF against 0.0.0.0 in github.com/imgproxy/imgproxy

Affected products

  • Go github.com/imgproxy/imgproxy/v3
  • Go github.com/imgproxy/imgproxy/v2
  • Go github.com/imgproxy/imgproxy

Related threats