CVE-2026-101910: Server-Side Request Forgery Bypass via NAT64 Local-Use Address Range in ip-address Library
Vulnerability ID: CVE-2026-101910
CVSS Score: 6.9
Published: 2026-09-28
A validation bypass vulnerability exists in the npm package ip-address from version 10.2.0 to 10.5.1. The library's Address6.isPrivate() classifier fails to recognize the NAT64 local-use prefix range 64:ff9b:1::/48 as a restricted, private subnet. In networks implementing NAT64 routing configurations, an attacker can exploit this flaw to execute Server-Side Request Forgery (SSRF) and bypass local trust-boundary validations.
TL;DR
The ip-address library fails to identify the NAT64 local-use range 64:ff9b:1::/48 as private, enabling unauthenticated attackers to bypass SSRF validation checks and access internal network environments.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918: Server-Side Request Forgery (SSRF)
- Attack Vector: Network (Unauthenticated)
- CVSS v4.0 Score: 6.9 (Medium)
- EPSS Score / Percentile: Not available / No active threat intel indicators
- Exploit Status: poc
- KEV Status: Not listed on CISA KEV
Affected Systems
- Node.js environments implementing the
ip-addressnpm package for hostname/IP resolution sanitization. - Containerized services operating in dual-stack IPv4/IPv6 networks utilizing NAT64 local-use prefix routing.
-
ip-address: >= 10.2.0, < 10.5.1 (Fixed in:
10.5.1)
Code Analysis
Commit: ab3dc88
Fix isPrivate evaluation for NAT64 local-use ranges
@@ -1375,7 +1383,7 @@ export class Address6 {
return embedded.isPrivate();
}
- return this.isULA();
+ return this.isULA() || this.isHostInSubnet(NAT64_LOCAL_USE_SUBNET);
}
...
+const NAT64_LOCAL_USE_SUBNET = new Address6('64:ff9b:1::/48');
Mitigation Strategies
- Upgrade the ip-address dependency to version 10.5.1 or higher.
- Implement a manual subnet validation check on outbound IPv6 addresses using the 64:ff9b:1::/48 subnet mask.
- Configure network security groups and ingress/egress rules to restrict outbound calls from critical microservices to NAT64 translators.
Remediation Steps:
- Identify all projects and package files using the
ip-addresslibrary within the scope of version 10.2.0 to 10.5.0. - Execute
npm install ip-address@10.5.1or modify thepackage.jsonlockfile to lock dependencies on version 10.5.1. - Incorporate the NAT64 local-use check
64:ff9b:1::/48in any localized IP classification wrappers if library upgrades cannot be completed immediately. - Deploy network-level policies preventing application containers from querying internal network assets or sensitive endpoints like the Cloud Metadata API.
References
- NVD - CVE-2026-101910 Detail
- GitHub Security Advisory (GHSA-2vr4-cq9g-pvrc)
- ip-address Release Version Tag v10.5.1
Read the full report for CVE-2026-101910 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)