CVE-2025-2691
Severity CVSS v4.0:
HIGH
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
23/03/2025
Last modified:
29/04/2026
Description
Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.
Impact
Base Score 4.0
7.80
Severity 4.0
HIGH
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nossrf_project:nossrf:*:*:*:*:*:*:*:* | 1.0.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



