Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-8267

21
FAUCET Score

CVE-2025-8267 is a Server-Side Request Forgery (SSRF) vulnerability affecting versions of the 'ssrfcheck' package prior to 1.2.0, specifically the 'felipperegazio ssrf_check' product. The flaw stems from an incomplete denylist that fails to block the 224.0.0.0/4 multicast IP range, allowing attackers to craft requests to these addresses. With a CVSS score of 5.3 (Medium), this vulnerability is network-exploitable with low complexity, requiring no privileges or user interaction, and could lead to information disclosure (I:L). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.2.0CPE matchmatch criteria
cpe:2.3:a:felipperegazio:ssrf_check:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 23rd percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: ssrfcheckFixed in: 1.2.0

Vendor Advisories (2)

npmGHSA-p4hc-9pjh-55c8high

ssrfcheck: SSRF Bypass Caused by Failure to Classify Reserved IP Address Space as Invalid

May 5, 2026
npmGHSA-c2fv-2fmj-9xrxhigh

Duplicate Advisory: ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability

Jul 28, 2025

References

gist.github.com / lirantal/2976840639df824cb3abe60d13c65e04
ExploitThird Party Advisory
github.com / felippe-regazio/ssrfcheck/commit/9507b49fd764f2a1a1d1e3b9ee577b7545e6950e
Patch
github.com / felippe-regazio/ssrfcheck/issues/5
Issue Tracking
security.snyk.io / vuln/SNYK-JS-SSRFCHECK-9510756
ExploitThird Party Advisory