CVE-2026-101913 - Medium Severity Vulnerability
Vulnerable Library - ip-address-10.3.1.tgz
A library for parsing IPv4 and IPv6 IP addresses in node and the browser.
Library home page: https://registry.npmjs.org/ip-address/-/ip-address-10.3.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
- chromedriver-149.0.4.tgz (Root Library)
- proxy-agent-8.0.2.tgz
- socks-proxy-agent-10.1.0.tgz
- socks-2.8.9.tgz
- ❌ ip-address-10.3.1.tgz (Vulnerable Library)
Found in HEAD commit: 4f2a7131d9cdb72c0b6ec2df38bf840af14e67bb
Found in base branch: main
Vulnerability Details
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1.
Publish Date: 2026-09-28
URL: CVE-2026-101913
CVSS 3 Score Details (5.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
CVE-2026-101913 - Medium Severity Vulnerability
A library for parsing IPv4 and IPv6 IP addresses in node and the browser.
Library home page: https://registry.npmjs.org/ip-address/-/ip-address-10.3.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /package.json
Dependency Hierarchy:
Found in HEAD commit: 4f2a7131d9cdb72c0b6ec2df38bf840af14e67bb
Found in base branch: main
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1.
Publish Date: 2026-09-28
URL: CVE-2026-101913
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.