VYPR
High severity8.2NVD Advisory· Published Mar 23, 2025· Updated Apr 29, 2026

CVE-2025-2691

CVE-2025-2691

Description

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nossrfnpm
< 1.0.41.0.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.