The Ssri Project maintains a utility library focused on Server-Side Request Forgery (SSRF) mitigation, a narrowly scoped but strategically important component embedded in development and deployment pipelines. Its observed vulnerability surface centers on resource-consumption and validation issues, the kind of flaw that can affect downstream consumers of the library across diverse application contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ssri Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27290HIGH ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. Malicious SRIs could take an extremely long time to process, | Mar 12, 2021 | 7.5 | 26 | NO | NO |
CVE-2018-7651MEDIUM index.js in the ssri module before 5.2.2 for Node.js is prone to a regular expression denial of service vulnerability in strict mode functionality via a long base64 hash string. | Mar 4, 2018 | 5.9 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ssri Project.
Media articles that mention a CVE ID that affects a product developed by Ssri Project — matched by CVE ID, not by vendor name.