PT-2025-37864 · Npm+1 · Ip+1

Cosmosofcyberspace

·

Published

2025-01-01

·

Updated

2025-09-24

·

CVE-2025-59437

CVSS v3.1

3.2

Low

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ip (aka node-ip) package versions through 2.0.1
Description The ip (aka node-ip) package may allow Server-Side Request Forgery (SSRF) due to the improper categorization of the IP address value 0 as globally routable via the isPublic function. This issue stems from an incomplete fix for a previously identified problem. Connection attempts to the IP address 0 (or 0.0.0.0) may be interpreted as attempts to connect to 127.0.0.1 in certain application versions and operating systems.
Recommendations Update to a version of the ip (aka node-ip) package later than 2.0.1.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-59437

Affected Products

Debian
Ip