DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-101913: CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF

CVE-2026-101913: Link-Local Address Validation Bypass in ip-address Library Enables SSRF

Vulnerability ID: CVE-2026-101913
CVSS Score: 6.3
Published: 2026-09-28

A validation bypass exists in the ip-address library prior to version 10.5.1. The Address6.isLinkLocal() method inaccurately restricted link-local classifications to the fe80::/64 subnet, failing to cover the complete RFC 4291 fe80::/10 allocation. This allows attackers to bypass SSRF filters relying on this library to safeguard local network boundaries.

TL;DR

A logic bug in the ip-address library (< 10.5.1) causes isLinkLocal() to fail to identify valid link-local IPv6 addresses outside the fe80::/64 subnet, enabling SSRF bypasses.


Technical Details

  • CWE ID: CWE-697, CWE-918
  • Attack Vector: Network (Unauthenticated)
  • CVSS v4.0: 6.3 (Medium)
  • EPSS Status: Not yet listed
  • Impact: Bypass of SSRF network boundary controls
  • Exploit Status: No active wild exploitation tracked
  • KEV Status: Not listed

Affected Systems

  • Applications utilizing the JavaScript/TypeScript 'ip-address' package for security validation.

Mitigation Strategies

  • Upgrade 'ip-address' dependency to 10.5.1 or newer.
  • Apply a manual regex/prefix check for fe80::/10 if patching is blocked.
  • Establish firewall policies blocking outbound link-local traffic from application instances.

Remediation Steps:

  1. Audit lockfiles for vulnerable versions of 'ip-address' (< 10.5.1).
  2. Run standard package manager update commands to pull the patched version.
  3. Deploy network egress rules to isolate the application container/host from link-local services.

References


Read the full report for CVE-2026-101913 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)