Critical Vulnerabilities 2021 Incident #60 CVE-2021-28918

node-netmask SSRF

Estimated Financial Impact
278K dependent repos
Blast Radius
CVSS 9.1; 238M+ total downloads

What Happened

Improper IP address parsing in node-netmask (CVSS 9.1) enabled SSRF, remote file inclusion, and local file inclusion bypasses. The package had ~3M weekly downloads, 238M+ total downloads, and ~278,000 dependent repositories.

✓

Risk Guard: Caught

VULN_RECENT_FREQUENCY + maintainer health preconditions

Risk Guard Check Codes That Flag This Incident

VULN_RECENT_FREQUENCY

How Every Tool Performed

1 Caught 0 Partial 5 After damage 0 Missed
Tool Verdict Details
OSS Risk Guard Caught VULN_RECENT_FREQUENCY + maintainer health preconditions
Socket After damage Detects after CVE published
Snyk After damage CVE detection after publication; reactive not proactive
Sonatype (Nexus) After damage Detects after CVE published
Black Duck After damage Detects after CVE published
Endor Labs After damage CVE detection + reachability analysis after publication; reactive
← PAC-Resolver SSRF/RCE Equifax / Apache Struts →