Vulnerability Description
imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose services on the local host. This vulnerability is fixed in 3.27.2.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/imgproxy/imgproxy/commit/3d4fed6842aa8930ec224d0ad75b0079b858
- https://github.com/imgproxy/imgproxy/security/advisories/GHSA-j2hp-6m75-v4j4
FAQ
What is CVE-2025-24354?
CVE-2025-24354 is a vulnerability with a CVSS score of 5.3 (MEDIUM). imgproxy is server for resizing, processing, and converting images. Imgproxy does not block the 0.0.0.0 address, even with IMGPROXY_ALLOW_LOOPBACK_SOURCE_ADDRESSES set to false. This can expose servic...
How severe is CVE-2025-24354?
CVE-2025-24354 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24354?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.