{"id":"GHSA-c2fv-2fmj-9xrx","summary":"Duplicate Advisory: ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-p4hc-9pjh-55c8. This link is maintained to preserve external references.\n\n### Original Description\nVersions of the package ssrfcheck below 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid. This oversight allows attackers to craft requests targeting these multicast addresses.","modified":"2026-09-10T03:50:57.859423231Z","published":"2025-07-28T06:30:23Z","withdrawn":"2026-05-05T20:25:33Z","database_specific":{"github_reviewed_at":"2025-07-28T16:42:51Z","nvd_published_at":"2025-07-28T05:16:20Z","cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8267"},{"type":"WEB","url":"https://github.com/felippe-regazio/ssrfcheck/issues/5"},{"type":"WEB","url":"https://github.com/felippe-regazio/ssrfcheck/commit/9507b49fd764f2a1a1d1e3b9ee577b7545e6950e"},{"type":"WEB","url":"https://gist.github.com/lirantal/2976840639df824cb3abe60d13c65e04"},{"type":"PACKAGE","url":"https://github.com/felippe-regazio/ssrfcheck"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-SSRFCHECK-9510756"}],"affected":[{"package":{"name":"ssrfcheck","ecosystem":"npm","purl":"pkg:npm/ssrfcheck"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-c2fv-2fmj-9xrx/GHSA-c2fv-2fmj-9xrx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}