Medium · 4.6 Node.js & npm CVE-2026-101910 GHSA-2vr4-cq9g-pvrc CVE-2026-101911 GHSA-h3mg-xc3c-68pw
Four ip-address npm Package Flaws Allow SSRF Trust-Boundary Bypass and Denial of Service
The npm package ip-address, used to parse and classify IPv4/IPv6 addresses, has four fixed vulnerabilities that can let attacker-controlled addresses bypass trust-boundary checks (SSRF) or cause a denial of service through oversized input strings.
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 1w ago · view ↗
- GitHub Advisory Database database 1w ago · view ↗
- GitHub Advisory Database database 1w ago · view ↗
- GitHub Advisory Database database 1w ago · view ↗
AI summary
ip-address is a JavaScript library for parsing and classifying IPv4 and IPv6 addresses, commonly used by applications to decide whether a given address is private, loopback, link-local, or inside an allowed subnet. Four separate vulnerabilities have been disclosed and fixed in this library. Three involve incorrect address classification that can let an attacker-supplied address slip past a trust-boundary check, creating conditions for Server-Side Request Forgery (SSRF) or access to hosts that should be out of scope. The fourth involves unbounded string handling that can cause a synchronous stall, high memory use, or process termination. None of the issues are known to be actively exploited, and no public exploit code has been reported.
What happened
Four vulnerabilities were disclosed in the ip-address npm package, all involving how the library classifies or parses IP addresses: - CVE-2026-101910 (GHSA-2vr4-cq9g-pvrc): The Address6 isPrivate classifier does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications combining isPrivate, isLoopback, and isLinkLocal for trust decisions can treat an internal IPv4 destination encoded via this range as external. - CVE-2026-101913 (GHSA-rpw4-54j3-4h4q): The Address6 isLinkLocal method only recognizes the narrower fe80::/64 range instead of the full fe80::/10 IPv6 link-local range. An address elsewhere in fe80::/10 can pass a trust check relying on isLinkLocal, even though getType and getScope correctly identify it as link-local, creating an inconsistency. - CVE-2026-101912 (GHSA-j6r3-76f7-8jcv): The isInSubnet and isHostInSubnet methods compare masked binary strings without checking that both addresses belong to the same IP family (IPv4 vs IPv6). If the leading bits happen to match, a cross-family comparison can incorrectly classify an address as contained in a subnet it does not belong to. - CVE-2026-101911 (GHSA-h3mg-xc3c-68pw): The Address6 constructor, isValid, and parse code accept unbounded input strings. Invalid characters are expanded into large diagnostic messages, which can cause a synchronous stall and high transient memory use on megabyte-scale input, an invalid string length exception around 16 MiB, and process termination around 32 MiB.
Technical cause
The three classification issues (CVE-2026-101910, CVE-2026-101912, CVE-2026-101913) stem from incomplete or incorrect range checks in the library's address classification logic in src/ipv6.ts and src/common.ts: a missing NAT64 range in isPrivate, a too-narrow link-local prefix in isLinkLocal, and a subnet-containment comparison in isInSubnet/isHostInSubnet that does not verify IP family before comparing masked bit strings. The resource-consumption issue (CVE-2026-101911) stems from the Address6 constructor, isValid, and parse functions accepting input strings without an upper length bound, allowing invalid characters to be expanded via RE_BAD_CHARACTERS into diagnostic output whose size scales with the input.
Why it matters
Applications frequently use address classification functions like isPrivate, isLoopback, isLinkLocal, and isInSubnet to enforce trust boundaries — for example, to block requests to internal network ranges and prevent Server-Side Request Forgery (SSRF). Because three of these four issues cause the library to misclassify addresses, an attacker who can supply a target address or URL may be able to reach hosts the application intended to block. Exploitation of the NAT64-related issue (CVE-2026-101910) depends on the server's network using an operator-selected NAT64 prefix within the local-use range, so its applicability varies by deployment. The fourth issue (CVE-2026-101911) can degrade availability by causing a synchronous stall or crashing the process when a sufficiently large, attacker-controlled field is passed into Address6 parsing without an earlier length bound.
Who is affected
Any application that depends on the ip-address npm package and uses its isPrivate, isLoopback, isLinkLocal, isInSubnet, isHostInSubnet, isValid, or Address6 parsing functions to make trust-boundary or allowlist/denylist decisions, or to process attacker-influenced address strings, may be affected depending on which vulnerable versions are in use.
Affected versions
- CVE-2026-101910 (NAT64 isPrivate bypass): ip-address versions from 10.2.0 up to and including 10.5.0. Fixed in 10.5.1. - CVE-2026-101913 (isLinkLocal fe80::/64 vs fe80::/10): ip-address versions up to and including 10.5.0. Fixed in 10.5.1. - CVE-2026-101912 (cross-family subnet comparison): ip-address versions up to and including 10.7.0. Fixed in 10.7.1. - CVE-2026-101911 (unbounded parse input / resource consumption): ip-address versions up to and including 10.7.0. Fixed in 10.7.1.
Fixes and mitigation
All four issues are fixed by the vendor. CVE-2026-101910 and CVE-2026-101913 are fixed in ip-address version 10.5.1. CVE-2026-101911 and CVE-2026-101912 are fixed in ip-address version 10.7.1. Updating to version 10.7.1 addresses all four issues, since it is later than 10.5.1.
Recommended action
Update the ip-address npm package to version 10.7.1 or later. Review any code that relies on isPrivate, isLoopback, isLinkLocal, isInSubnet, or isHostInSubnet for trust-boundary, allowlist, or denylist decisions to confirm it behaves as expected after upgrading. Where attacker-controlled strings are passed to Address6 parsing or isValid, ensure an appropriate length bound is enforced before parsing, independent of the library's own fix.
PatchBriefing score
4.6 / 10 · Medium
Official CVSS: 6.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
Each of the four vulnerabilities carries a patchwire_score in the 4.3–4.6 range, reflecting a moderate CVSS base score (6.3–6.9), network-based attack vector requiring no user interaction and no privileges, but with no known exploitation in the wild, no public exploit code, and an available fix. None are flagged as known exploited or associated with ransomware activity. The scores reflect a real but conditional risk: exploitation depends on specific application logic (how classification functions are used) or specific network configuration (e.g., NAT64 prefix choice), rather than being universally exploitable out of the box.
Affected versions
- ip-address >= 10.2.0, <= 10.5.0
- vulnerable
- ≥ 10.5.1
- patched
- ip-address <= 10.7.0
- vulnerable
- ≥ 10.7.1
- patched
- ip-address <= 10.7.0
- vulnerable
- ≥ 10.7.1
- patched
- ip-address <= 10.5.0
- vulnerable
- ≥ 10.5.1
- patched
Reported fixes
All four issues are fixed by the vendor. CVE-2026-101910 and CVE-2026-101913 are fixed in ip-address version 10.5.1. CVE-2026-101911 and CVE-2026-101912 are fixed in ip-address version 10.7.1. Updating to version 10.7.1 addresses all four issues, since it is later than 10.5.1.
How this was built
8 source records were collected, matched and used to prepare the report above.
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email