CVE Vulnerabilities

CVE-2024-28607

Incorrect Behavior Order: Validate Before Canonicalize

Published: Mar 11, 2025 | Modified: Mar 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Potential Mitigations

References