Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-pw25-c82r-75mm

MediumCVSS 5.5 / 10
Published Aug 25, 2025·Last modified Aug 26, 2025
Affected Components(0)

No affected components available

Description

request-filtering-agent versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass IP address filtering, while HTTP requests are correctly blocked.

Impact:

Vulnerable patterns (requests that should be blocked but are allowed):

  • https://127.0.0.1:443/api
  • https://127.0.0.1:8443/admin
  • Any HTTPS request using direct IP address https://127.0.0.1

This vulnerability primarily affects services using self-signed certificates on 127.0.0.1.

Not affected (correctly blocked in all versions):

  • http://127.0.0.1:80/api - HTTP requests are properly blocked
  • https://localhost:443/api - Domain-based requests trigger DNS lookup and are blocked
  • http://localhost:80/api - Domain-based HTTP requests are blocked
  • Requests to other private IPs like 192.168.x.x, 10.x.x.x, 172.16.x.x

This allows attackers to potentially access internal HTTPS services running on localhost, bypassing the library's SSRF protection. The vulnerability is particularly dangerous when the application accepts user-controlled URLs and internal services are only protected by network-level restrictions.

Fixed in 2.0.0

This vulnerability has been fixed in request-filtering-agent version 2.0.0. Users should upgrade to version 2.0.0 or later.

Root Cause:The HTTPS agent fails to validate direct IP addresses like https://127.0.0.1 during TLS connection setup, allowing them to bypass the security filter.

Details: https://github.com/azu/request-filtering-agent-https127-test

Thanks Luca

Risk Scores
Base Score
5.5

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability.

Threat Intelligence
2.7

Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.

EPSS
0.46%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard