The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as 128.0.0.0/1) that causes resource exhaustion. Update get-ip-range dependency to 4.0.0 or above.
{
"github_reviewed": true,
"github_reviewed_at": "2021-03-19T22:50:19Z",
"severity": "HIGH",
"nvd_published_at": "2021-02-11T18:15:00Z",
"cwe_ids": [
"CWE-400"
]
}