VDB
Sign up
LOW

GHSA-78xj-cgh5-2h22

NPM IP package incorrectly identifies some private IP addresses as public

Quick fix

GHSA-78xj-cgh5-2h22 — ip: upgrade to the fixed version with the command below.

npm install ip@2.0.1

Details

The `isPublic()` function in the NPM package `ip` doesn't correctly identify certain private IP addresses in uncommon formats such as `0x7F.1` as private. Instead, it reports them as public by returning `true`. This can lead to security issues such as Server-Side Request Forgery (SSRF) if `isPublic()` is used to protect sensitive code paths when passed user input. Versions 1.1.9 and 2.0.1 fix the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ip
Introduced in: 2.0.0Fixed in: 2.0.1
Fixnpm install ip@2.0.1
npm/ip
Introduced in: 0Fixed in: 1.1.9
Fixnpm install ip@1.1.9

References