logo

Critical Flaw Found In Widely Used Netmask Open Source Module

ID: befc063d-ded8-59e4-8cd1-968c8b655cd1

STIX ID: report--befc063d-ded8-59e4-8cd1-968c8b655cd1

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2021-03-30

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Security researchers discovered that the netmask NPM library misparses IPv4 addresses containing octal notations, causing trusted/private and public IPs to be misclassified; this flaw (CVE-2021-28918) can enable SSRF, local/remote file inclusion and other attacks against applications that rely on netmask for IP filtering. Patches (v2.0.0 / v2.0.1) were released but few downloads indicate most dependent projects remain vulnerable, and researchers warn similar parsing issues may exist in other libraries and languages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.