Hardcoded IP Address Vulnerability¶
Is a hardcoded IP a vulnerability?¶
An IP literal is not inherently a security vulnerability. A fixed bind address, an approved network rule or an intentionally pinned endpoint can be valid. Review the connection's purpose, transport, authentication and change process. Embedded addresses often cause deployment or availability problems; severity needs a demonstrated security consequence.
Node.js endpoint example¶
Here the concrete security issue is cleartext transport to a service; the embedded endpoint also makes environment changes difficult. The documentation address is fictional.
Problematic deployment choice:
const endpoint = new URL('http://192.0.2.10/status');
Safer: validate a deployment-owned HTTPS endpoint.
function endpointFromConfig(value) {
if (typeof value !== 'string') throw new Error('Missing endpoint');
const url = new URL(value);
if (url.protocol !== 'https:' ||
url.hostname !== 'reports.example.test' || url.port !== '' ||
url.username || url.password || url.pathname !== '/status' ||
url.search || url.hash) {
throw new Error('Unapproved endpoint');
}
return url;
}
const endpoint = endpointFromConfig(process.env.REPORTS_STATUS_URL);
The Node.js URL API separates components for validation. Replace the fictional host with the intended service in reviewed application configuration. The environment variable must come from trusted deployment configuration, not a request parameter. Restrict configuration write access, keep certificate verification enabled and apply the service's authentication policy.
Moving an address into an environment variable or replacing it with DNS is not, by itself, a security fix. URL validation also does not constrain DNS resolution or redirect targets; an HTTP client must enforce the intended redirect and network policy.
Regression check¶
Accept only the intended HTTPS endpoint. Reject missing configuration, HTTP, another host, user information and an unexpected path. Confirm legitimate environment changes through deployment tests. See TLS verification and SSRF when requests can influence outbound destinations.