The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as 128.0.0.0/1) that causes resource exhaustion.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-27191.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "4.0.0" } ] }, { "events": [ { "introduced": "0" }, { "fixed": "4.0.0" } ] } ]