Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2025-24354

Disclosure Date: January 27, 2025 (last updated January 28, 2025)
imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
0
Attacker Value
Unknown

CVE-2023-30019

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
imgproxy <=3.14.0 is vulnerable to Server-Side Request Forgery (SSRF) due to a lack of sanitization of the imageURL parameter.
Attacker Value
Unknown

CVE-2023-1496

Disclosure Date: March 19, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.