The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
Exploitability
AV:LAC:HPR:NUI:NScope
S:UImpact
C:NI:LA:N2.9/CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NOther