Improper IP address parsing in node-netmask (CVSS 9.1) enabled SSRF, remote file inclusion, and local file inclusion bypasses. The package had ~3M weekly downloads, 238M+ total downloads, and ~278,000 dependent repositories.
VULN_RECENT_FREQUENCY + maintainer health preconditions
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | VULN_RECENT_FREQUENCY + maintainer health preconditions |
| Socket | After damage | Detects after CVE published |
| Snyk | After damage | CVE detection after publication; reactive not proactive |
| Sonatype (Nexus) | After damage | Detects after CVE published |
| Black Duck | After damage | Detects after CVE published |
| Endor Labs | After damage | CVE detection + reachability analysis after publication; reactive |