CVE-2026-101912: Cross-Family IP Address Subnet Containment Logic Bypass in ip-address Library
Vulnerability ID: CVE-2026-101912
CVSS Score: 6.3
Published: 2026-09-29
The ip-address library is vulnerable to a logical bypass in its subnet containment methods. The functions isInSubnet() and isHostInSubnet() do not verify that compared addresses belong to the same IP family before performing masking checks. Under specific circumstances, an IPv6 address can share leading bit patterns with an IPv4 subnet, causing the containment check to evaluate as true. This allows attackers to bypass access control lists, firewalls, and server-side request forgery protection layers in applications relying on the library.
TL;DR
A logical error in the ip-address library allows cross-family IP comparisons (IPv4 vs. IPv6) to collide. This enables attackers to bypass IP-based filters and access controls by submitting crafted IPv6 addresses that mimic private IPv4 subnets.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-697 / CWE-843
- Attack Vector: Network (AV:N)
- CVSS v4.0 Score: 6.3 (Medium)
- EPSS Score: 0.0037 (Percentile: 28.38%)
- Impact: Partial Integrity (ACL/SSRF Filter Bypass)
- Exploit Status: Proof-of-Concept (PoC) Available
- KEV Status: Not Listed
Affected Systems
- Node.js applications using the ip-address npm library
-
ip-address: < 10.7.1 (Fixed in:
10.7.1)
Code Analysis
Commit: 1343629
Fix cross-family containment checks by checking bit string length matches before mask comparison
Commit: 469ead1
Enforce input length limits to prevent parser denial of service
Mitigation Strategies
- Upgrade to ip-address v10.7.1 or later
- Manually restrict address family processing on entry points
- Add length constraints to raw IP parser inputs
- Employ network-layer firewall configurations as defense-in-depth
Remediation Steps:
- Identify vulnerable dependencies by running 'npm ls ip-address' or examining the yarn/pnpm lockfile.
- Update package.json dependencies to require 'ip-address': '^10.7.1'.
- Execute dependency updates inside the development environment to rebuild the lockfile.
- Deploy the updated build to production environments.
References
- GitHub Security Advisory (GHSA-j6r3-76f7-8jcv)
- Patch Commit
- Release tag v10.7.1
- NVD Record Details
- CVE.org Record Details
- Wiz Vulnerability Database Details
Read the full report for CVE-2026-101912 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)