Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22851 | ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability |
Github GHSA |
GHSA-c2fv-2fmj-9xrx | ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability |
Github GHSA |
GHSA-p4hc-9pjh-55c8 | ssrfcheck: SSRF Bypass Caused by Failure to Classify Reserved IP Address Space as Invalid |
Thu, 07 Aug 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Felipperegazio
Felipperegazio ssrf Check |
|
| CPEs | cpe:2.3:a:felipperegazio:ssrf_check:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Felipperegazio
Felipperegazio ssrf Check |
Tue, 29 Jul 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ssrfcheck
Ssrfcheck ssrfcheck |
|
| Vendors & Products |
Ssrfcheck
Ssrfcheck ssrfcheck |
Mon, 28 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Jul 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ranges. Specifically, the package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid. This oversight allows attackers to craft requests targeting these multicast addresses. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-07-28T16:01:35.358Z
Reserved: 2025-07-27T12:56:36.513Z
Link: CVE-2025-8267
Updated: 2025-07-28T16:01:31.611Z
Status : Analyzed
Published: 2025-07-28T05:16:20.673
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-8267
No data.
OpenCVE Enrichment
Updated: 2025-07-29T10:01:02Z
EUVD
Github GHSA