Low severity2.9NVD Advisory· Published Mar 11, 2025· Updated Apr 15, 2026
CVE-2024-28607
CVE-2024-28607
Description
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.