Filtered by vendor Nossrf Project Subscriptions
Filtered by product Nossrf Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-2691 1 Nossrf Project 1 Nossrf 2025-03-26 8.2 High
Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname that resolves to a local or reserved IP address space and bypass the SSRF protection mechanism.