{"id":"CVE-2017-0909","aliases":["GHSA-3v3c-r5v2-68ph"],"url":"https://o3.security/vulnerability/CVE-2017-0909","summary":"private_address_check contains Incomplete List of Disallowed Inputs","details":"The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.","published":"2017-11-16T22:29:00.267Z","modified":"2026-07-08T12:42:06.884946Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"private_address_check","fixedVersion":"0.4.1"}],"fix":{"url":"https://github.com/jtdowney/private_address_check/pull/3","label":"jtdowney/private_address_check#3"},"references":[{"type":"REPORT","url":"https://github.com/jtdowney/private_address_check/pull/3"},{"type":"FIX","url":"https://hackerone.com/reports/288950"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:42:06.884946Z"}}