CVE-2025-2691
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-2691 is a newly disclosed Server-Side Request Forgery (SSRF) vulnerability affecting versions of the nossrf package prior to 1.0.4. An attacker can exploit this weakness by supplying a maliciously crafted hostname that points to a local or restricted IP address space. This bypasses the intended SSRF protection mechanism, potentially allowing unauthorized access or data theft from the affected system. The vulnerability could have significant security implications, particularly for applications that rely on the nossrf package for input validation. It is recommended that users upgrade to the latest version of the package to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.