async-upnp-client is vulnerable to Server-Side Request Forgery (SSRF)
31
Low Risk
The UPnP client factory consumes service controlURL, SCPDURL, and eventSubURL values from a device description without verifying they point to the device's own host, and SSDP discovery location validation relies on substring matching. A rogue or compromised UPnP device on the network can supply crafted or obfuscated URLs that resolve to loopback, unspecified, or IPv4 link-local cloud-metadata addresses. This can steer the client into issuing requests to internal services it should not reach, resulting in server-side request forgery. The fix validates that service URL elements resolve to the device's own host and parses discovery locations with proper URL/IP parsing that rejects obfuscated internal addresses.
You are affected if you are using a version that falls within the vulnerable range.
async-upnp-client is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.9.0 - 0.47.0.
Upgrade the async-upnp-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant