Junglewise Threat Intelligence

ssrfcheck incomplete IP address deny list leading to SSRF

Severity: low · CVSS 3.1 · Published 2025-07-28

Vendors: npm.

Executive brief

ssrfcheck is a Node.js library used to validate and block requests to reserved IP address ranges to prevent server-side request forgery (SSRF) attacks. The library fails to properly block multicast address ranges (224.0.0.0/4), allowing attackers to bypass SSRF protections and reach reserved network addresses. This could enable attackers to access internal services, metadata endpoints, or other sensitive resources that should be inaccessible.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) caused by an incomplete IP address deny list in the ssrfcheck library (CWE-918). The package fails to classify the reserved multicast IP address space 224.0.0.0/4 as invalid, allowing attackers to craft HTTP requests targeting these multicast addresses. The vulnerability affects all versions before 1.2.0, with a fix available in version 1.2.0 and later. No authentication is required; exploitation requires network access to the application using the vulnerable library and the ability to control request URLs.

Affected products

  • felippe-regazio ssrfcheck before 1.2.0

Timeline

  • 2025-07-28: disclosed
  • 2025-06-25: other: Issue opened by maintainer
  • 2026-05-05: other: Advisory withdrawn as duplicate of GHSA-p4hc-9pjh-55c8

References

Related threats