Vulnerability CVE-2023-24623


Published: 2023-01-30

Description:
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.

 References:
https://github.com/hakobe/paranoidhttp/compare/v0.2.0...v0.3.0
https://github.com/hakobe/paranoidhttp/blob/master/CHANGELOG.md#v030-2023-01-19
https://github.com/hakobe/paranoidhttp/commit/07f671da14ce63a80f4e52432b32e8d178d75fd3

Copyright 2026, cxsecurity.com

 

Back to Top