Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2026-101913

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101912

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101911

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101910

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48....

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-69198

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-69192

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser,...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-54272

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType()...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-42338

Medium priority
Needs evaluation

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML...

1 affected package

node-ip-address

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip-address Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2025-59437

Medium priority
Needs evaluation

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for...

1 affected package

node-ip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-59436

Medium priority
Needs evaluation

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for...

1 affected package

node-ip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-ip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages