The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html
- https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/
- https://github.com/Blackfly0537/test
- https://github.com/DevSecCube/damn-vulnerable-sca
- https://github.com/SCA-Testing-Org/Damn-Vulnerable-Sca-E2E
- https://github.com/Sharpforce/cybersecurity
- https://github.com/aparnalaxmi07/sca-goat
- https://github.com/cleypanw/prisma-cloud-kubernetes-exploitation-demo
- https://github.com/harekrishnarai/Damn-vulnerable-sca
- https://github.com/harshit-kochar/Damn-vulnerable-sca
- https://github.com/lucasarasa/exec-docker-abr-2025
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/rdosec/Damn-vulnerable-sca
- https://github.com/seal-community/patches
- https://github.com/vin01/bogus-cves
- https://github.com/webpod/ip