CVE-2025-57814
Last modified
CVE-2025-57814 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass IP address filtering, while HTTP requests are correctly blocked. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass IP address filtering, while HTTP requests are correctly blocked. This allows attackers to potentially access internal HTTPS services running on localhost, bypassing the library's SSRF protection. The vulnerability is particularly dangerous when the application accepts user-controlled URLs and internal services are only protected by network-level restrictions. This vulnerability has been fixed in request-filtering-agent version 2.0.0. Users should upgrade to version 2.0.0 or later.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-57814?
How severe is CVE-2025-57814?
How do I fix CVE-2025-57814?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-57809XGrammar is an open-source library for efficient, flexible, …7.5
- CVE-2025-5781Information Exposure Vulnerability in Hitachi Ops Center API…5.2
- CVE-2025-57810jsPDF is a library to generate PDFs in JavaScript. Prior to …7.5
- CVE-2025-57811Craft is a platform for creating digital experiences. From v…7.2
- CVE-2025-57812CUPS is a standards-based, open-source printing system, and …3.7
- CVE-2025-57813traQ is a messenger application built for Digital Creators C…5.9
- CVE-2025-57815Fides is an open-source privacy engineering platform. Prior …6.5
- CVE-2025-57816Fides is an open-source privacy engineering platform. Prior …7.5
- CVE-2025-57817Fides is an open-source privacy engineering platform. Prior …7.2
- CVE-2025-57818Firecrawl turns entire websites into LLM-ready markdown or s…6.3
- CVE-2025-57819FreePBX is an open-source web-based graphical user interface…9.8
- CVE-2025-5782A vulnerability, which was classified as critical, has been …6.3
Are you affected by CVE-2025-57814?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
