JoeScho/get-ip-range

JoeScho/get-ip-range

Releases0
Stars11
Simple utility to convert either CIDR notation or two IP addresses to an array of the range of IP addresses

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as 128.0.0.0/1) that causes resource exhaustion.