blob: efc97a847ba14379629d9e1d188d5de7d862ee8d [file] [log] [blame]
id: GO-2025-3422
modules:
- module: github.com/imgproxy/imgproxy
vulnerable_at: 1.1.8
- module: github.com/imgproxy/imgproxy/v2
vulnerable_at: 2.17.0
- module: github.com/imgproxy/imgproxy/v3
versions:
- fixed: 3.27.2
vulnerable_at: 3.27.1
summary: imgproxy is vulnerable to SSRF against 0.0.0.0 in github.com/imgproxy/imgproxy
cves:
- CVE-2025-24354
references:
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24354
- fix: https://github.com/imgproxy/imgproxy/commit/3d4fed6842aa8930ec224d0ad75b0079b858e081
- web: https://github.com/imgproxy/imgproxy/security/advisories/GHSA-j2hp-6m75-v4j4
source:
id: CVE-2025-24354
created: 2025-01-27T15:30:43.512148-05:00
review_status: UNREVIEWED