DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-101910: CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library

Vulnerability ID: CVE-2026-101910
CVSS Score: 6.9
Published: 2026-09-28

A validation bypass vulnerability exists in the npm package ip-address from version 10.2.0 to 10.5.1. The library's Address6.isPrivate() classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.

TL;DR

The ip-address library fails to identify the NAT64 local-use range 64:ff9b:1::/48 as private, enabling unauthenticated attackers to bypass SSRF validation checks and access internal network environments.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-918: Server-Side Request Forgery (SSRF)
  • Attack Vector: Network (Unauthenticated)
  • CVSS v4.0 Score: 6.9 (Medium)
  • EPSS Score / Percentile: Not available / No active threat intel indicators
  • Exploit Status: poc
  • KEV Status: Not listed on CISA KEV

Affected Systems

  • Node.js environments implementing the ip-address npm package for hostname/IP resolution sanitization.
  • Containerized services operating in dual-stack IPv4/IPv6 networks utilizing NAT64 local-use prefix routing.
  • ip-address: >= 10.2.0, < 10.5.1 (Fixed in: 10.5.1)

Code Analysis

Commit: ab3dc88

Fix isPrivate evaluation for NAT64 local-use ranges

@@ -1375,7 +1383,7 @@ export class Address6 {
       return embedded.isPrivate();
     }

-    return this.isULA();
+    return this.isULA() || this.isHostInSubnet(NAT64_LOCAL_USE_SUBNET);
   }
...
+const NAT64_LOCAL_USE_SUBNET = new Address6('64:ff9b:1::/48');
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade the ip-address dependency to version 10.5.1 or higher.
  • Implement a manual subnet validation check on outbound IPv6 addresses using the 64:ff9b:1::/48 subnet mask.
  • Configure network security groups and ingress/egress rules to restrict outbound calls from critical microservices to NAT64 translators.

Remediation Steps:

  1. Identify all projects and package files using the ip-address library within the scope of version 10.2.0 to 10.5.0.
  2. Execute npm install ip-address@10.5.1 or modify the package.json lockfile to lock dependencies on version 10.5.1.
  3. Incorporate the NAT64 local-use check 64:ff9b:1::/48 in any localized IP classification wrappers if library upgrades cannot be completed immediately.
  4. Deploy network-level policies preventing application containers from querying internal network assets or sensitive endpoints like the Cloud Metadata API.

References


Read the full report for CVE-2026-101910 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)