CVE-2025-8267 is a Server-Side Request Forgery (SSRF) vulnerability affecting versions of the 'ssrfcheck' package prior to 1.2.0, specifically the 'felipperegazio ssrf_check' product. The flaw stems from an incomplete denylist that fails to block the 224.0.0.0/4 multicast IP range, allowing attackers to craft requests to these addresses. With a CVSS score of 5.3 (Medium), this vulnerability is network-exploitable with low complexity, requiring no privileges or user interaction, and could lead to information disclosure (I:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.0CPE matchmatch criteria | cpe:2.3:a:felipperegazio:ssrf_check:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.