Source: node-ip-address
Version: 10.2.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-ip-address.

CVE-2026-54272[0]:
| ip-address is a library for parsing and manipulating IPv4 and IPv6
| addresses in JavaScript. Versions 10.1.1 through 10.2.0 are
| vulnerable to SSRF through misclassification of IPv4-mapped/NAT64
| IPv6 addresses. Address6.getType() classifies an address by matching
| it against a table of known IPv6 special-use prefixes, returning
| Global unicast when nothing matches. That table had no entry for the
| IPv4-mapped range (::ffff:0:0/96), so every mapped address fell
| through to Global unicast; NAT64 addresses matched their own NAT64 …
| labels. The boolean checks isLoopback, isUnspecified, and
| isMulticast compared getType() against a fixed label and so returned
| false, while isLinkLocal and isULA checked only the native IPv6
| ranges. The library already exposed isMapped4() and to4(), but did
| not apply them inside these checks, so a mapped or NAT64 address was
| never normalized to its embedded IPv4 address before classification.
| For IPv4-mapped addresses the host OS routes to the IPv4 stack, so
| the misclassification is reachable on any dual-stack host. For
| NAT64, the classification bypass is unconditional but end-to-end
| reachability additionally requires a NAT64/DNS64 gateway in the
| deployment network.This issue has been fixed in version 10.2.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54272
    https://www.cve.org/CVERecord?id=CVE-2026-54272
[1] 
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg

Regards,
Salvatore

Reply via email to