CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF
Vulnerability ID: CVE-2026-101913
CVSS Score: 6.3
Published: 2026-09-28
A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.
TL;DR
A logic bug in the ip-address library (< 10.5.1) causes isLinkLocal() to fail to identify valid link-local IPv6 addresses outside the fe80::/64 subnet, enabling SSRF bypasses.
Technical Details
- CWE ID: CWE-697, CWE-918
- Attack Vector: Network (Unauthenticated)
- CVSS v4.0: 6.3 (Medium)
- EPSS Status: Not yet listed
- Impact: Bypass of SSRF network boundary controls
- Exploit Status: No active wild exploitation tracked
- KEV Status: Not listed
Affected Systems
- Applications utilizing the JavaScript/TypeScript 'ip-address' package for security validation.
Mitigation Strategies
- Upgrade 'ip-address' dependency to 10.5.1 or newer.
- Apply a manual regex/prefix check for fe80::/10 if patching is blocked.
- Establish firewall policies blocking outbound link-local traffic from application instances.
Remediation Steps:
- Audit lockfiles for vulnerable versions of 'ip-address' (< 10.5.1).
- Run standard package manager update commands to pull the patched version.
- Deploy network egress rules to isolate the application container/host from link-local services.
References
Read the full report for CVE-2026-101913 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)