Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-28918

48
FAUCET Score

CVE-2021-28918 is a critical improper input validation vulnerability in the netmask npm package (v1.0.6 and below), affecting numerous dependent packages. This flaw allows unauthenticated remote attackers to bypass IP filtering, leading to Server-Side Request Forgery (SSRF), Remote File Inclusion (RFI), and Local File Inclusion (LFI attacks, potentially reaching critical internal hosts. With a CVSS score of 9.1 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability is easily exploitable over the network with low attack complexity, resulting in high confidentiality and integrity impacts. While not listed in CISA's KEV catalog, Nuclei templates exist for SSRF exploitation, and the vulnerability has garnered significant community discussion and media coverage, indicating widespread awareness and potential for active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.6CPE matchmatch criteria
cpe:2.3:a:netmask_project:netmask:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.66%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2021-28918 · Jul 6, 2021
This CVE's current EPSS score of 0.1666 is in the 93rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

npmpatch availablevia ghsa
Product: netmaskFixed in: 1.1.0
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/application-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-header-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/grc-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/mcm-topology-rhel8

Vendor Advisories (2)

npmGHSA-4c7m-wxvm-r7gccritical

Improper parsing of octal bytes in netmask

Apr 14, 2021
redhatCVE-2021-28918Important

nodejs-netmask: improper input validation of octal input data

Mar 29, 2021

References

github.com / advisories/GHSA-pch5-whg9-qr2r
Third Party Advisory
github.com / rs/node-netmask
Third Party Advisory
github.com / sickcodes/security/blob/master/advisories/SICK-2021-011.md
ExploitThird Party Advisory
rootdaemon.com / 2021/03/29/vulnerability-in-netmask-npm-package-affects-280000-projects
Third Party Advisory
security.netapp.com / advisory/ntap-20210528-0010
Third Party Advisory
bleepingcomputer.com / news/security/critical-netmask-networking-bug-impacts-thousands-of-applications
ExploitPress/Media CoverageThird Party Advisory
npmjs.com / package/netmask
ProductThird Party Advisory