CVE-2025-2691

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 23, 2025
Updated: Mar 26, 2025
CWE ID 918

Summary

CVE-2025-2691 is a newly disclosed Server-Side Request Forgery (SSRF) vulnerability affecting versions of the nossrf package prior to 1.0.4. An attacker can exploit this weakness by supplying a maliciously crafted hostname that points to a local or restricted IP address space. This bypasses the intended SSRF protection mechanism, potentially allowing unauthorized access or data theft from the affected system. The vulnerability could have significant security implications, particularly for applications that rely on the nossrf package for input validation. It is recommended that users upgrade to the latest version of the package to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share