DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-101912: CVE-2026-101912: Cross-Family IP Address Subnet Containment Logic Bypass in ip-address Library

CVE-2026-101912: Cross-Family IP Address Subnet Containment Logic Bypass in ip-address Library

Vulnerability ID: CVE-2026-101912
CVSS Score: 6.3
Published: 2026-09-29

The ip-address library is vulnerable to a logical bypass in its subnet containment methods. The functions isInSubnet() and isHostInSubnet() do not verify that compared addresses belong to the same IP family before performing masking checks. Under specific circumstances, an IPv6 address can share leading bit patterns with an IPv4 subnet, causing the containment check to evaluate as true. This allows attackers to bypass access control lists, firewalls, and server-side request forgery protection layers in applications relying on the library.

TL;DR

A logical error in the ip-address library allows cross-family IP comparisons (IPv4 vs. IPv6) to collide. This enables attackers to bypass IP-based filters and access controls by submitting crafted IPv6 addresses that mimic private IPv4 subnets.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-697 / CWE-843
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Score: 6.3 (Medium)
  • EPSS Score: 0.0037 (Percentile: 28.38%)
  • Impact: Partial Integrity (ACL/SSRF Filter Bypass)
  • Exploit Status: Proof-of-Concept (PoC) Available
  • KEV Status: Not Listed

Affected Systems

  • Node.js applications using the ip-address npm library
  • ip-address: < 10.7.1 (Fixed in: 10.7.1)

Code Analysis

Commit: 1343629

Fix cross-family containment checks by checking bit string length matches before mask comparison

Commit: 469ead1

Enforce input length limits to prevent parser denial of service

Mitigation Strategies

  • Upgrade to ip-address v10.7.1 or later
  • Manually restrict address family processing on entry points
  • Add length constraints to raw IP parser inputs
  • Employ network-layer firewall configurations as defense-in-depth

Remediation Steps:

  1. Identify vulnerable dependencies by running 'npm ls ip-address' or examining the yarn/pnpm lockfile.
  2. Update package.json dependencies to require 'ip-address': '^10.7.1'.
  3. Execute dependency updates inside the development environment to rebuild the lockfile.
  4. Deploy the updated build to production environments.

References


Read the full report for CVE-2026-101912 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)