{"id":"GHSA-6gww-qpm6-mc2g","summary":"Server-Side Request Forgery in ssrf-agent","details":"The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private.","aliases":["CVE-2021-23718"],"modified":"2026-03-13T21:56:54.489864Z","published":"2021-12-02T17:51:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-11-23T19:15:40Z","nvd_published_at":"2021-11-22T17:15:00Z","cwe_ids":["CWE-918"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23718"},{"type":"WEB","url":"https://github.com/welefen/ssrf-agent/commit/9607175acd0647d821bae4e8fcc3b712aca3fd2d#diff-e727e4bdf3657fd1d798edcd6b099d6e092f8573cba266154583a746bba0f346"},{"type":"PACKAGE","url":"https://github.com/welefen/ssrf-agent"},{"type":"WEB","url":"https://github.com/welefen/ssrf-agent/blob/cec2b85fe8886ad6926a247a3e059d8369ec022b/index.js%23L13"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20211203-0005"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SSRFAGENT-1584362"}],"affected":[{"package":{"name":"ssrf-agent","ecosystem":"npm","purl":"pkg:npm/ssrf-agent"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-6gww-qpm6-mc2g/GHSA-6gww-qpm6-mc2g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}