Your message dated Thu, 30 Jul 2026 13:19:57 +0000
with message-id <[email protected]>
and subject line Bug#1143057: fixed in node-ip-address 10.3.1-1
has caused the Debian Bug report #1143057,
regarding node-ip-address: CVE-2026-54272
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143057: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143057
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-ip-address
Version: 10.2.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for node-ip-address.
CVE-2026-54272[0]:
| ip-address is a library for parsing and manipulating IPv4 and IPv6
| addresses in JavaScript. Versions 10.1.1 through 10.2.0 are
| vulnerable to SSRF through misclassification of IPv4-mapped/NAT64
| IPv6 addresses. Address6.getType() classifies an address by matching
| it against a table of known IPv6 special-use prefixes, returning
| Global unicast when nothing matches. That table had no entry for the
| IPv4-mapped range (::ffff:0:0/96), so every mapped address fell
| through to Global unicast; NAT64 addresses matched their own NAT64 …
| labels. The boolean checks isLoopback, isUnspecified, and
| isMulticast compared getType() against a fixed label and so returned
| false, while isLinkLocal and isULA checked only the native IPv6
| ranges. The library already exposed isMapped4() and to4(), but did
| not apply them inside these checks, so a mapped or NAT64 address was
| never normalized to its embedded IPv4 address before classification.
| For IPv4-mapped addresses the host OS routes to the IPv4 stack, so
| the misclassification is reachable on any dual-stack host. For
| NAT64, the classification bypass is unconditional but end-to-end
| reachability additionally requires a NAT64/DNS64 gateway in the
| deployment network.This issue has been fixed in version 10.2.1.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-54272
https://www.cve.org/CVERecord?id=CVE-2026-54272
[1]
https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-ip-address
Source-Version: 10.3.1-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-ip-address, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-ip-address package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 30 Jul 2026 14:54:55 +0200
Source: node-ip-address
Architecture: source
Version: 10.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1143057
Changes:
node-ip-address (10.3.1-1) unstable; urgency=medium
.
* Team upload
* New upstream version (Closes: #1143057, CVE-2026-54272)
Checksums-Sha1:
a57f9f1cba3c8562bfe13f5c4543f03910ac96ba 2194 node-ip-address_10.3.1-1.dsc
8e10371605d378aa74435c27ee77fd61c1380565 110215
node-ip-address_10.3.1.orig.tar.gz
4e15fb99ce188bb70867a826f4582e8da61d507c 3276
node-ip-address_10.3.1-1.debian.tar.xz
Checksums-Sha256:
fd8e4c2ecdda20bdf290e922b68bc821cc5241f6b82130ea664f43c29167e324 2194
node-ip-address_10.3.1-1.dsc
d8147d926dcbdbe71956b350d2d84373836a87e9b48664e7cbb7b5c8b6e5a36b 110215
node-ip-address_10.3.1.orig.tar.gz
0918d8130eb14eeb59c4ed86afa78dc035492faff6997fee2b4762bf2e402e8c 3276
node-ip-address_10.3.1-1.debian.tar.xz
Files:
dffd22293188e3d53446926ae7816ab0 2194 javascript optional
node-ip-address_10.3.1-1.dsc
124b104aaec8b01bab081b1588b528e9 110215 javascript optional
node-ip-address_10.3.1.orig.tar.gz
bd62dca23981a75dfdaf2f6a2cdc0b1c 3276 javascript optional
node-ip-address_10.3.1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprSd4ACgkQ9tdMp8mZ
7unObQ//cgfIJITCw/imiZSTByBspsFz3zWurEZskxrYg3Y+WCzhz5WdnquZJ2Z6
3N92JscTUncW6pL0l7MoJXEvNFRU4ejYlH3RTcCaw3RHM3c+40lqeulm7/YiviOd
MvqbefVPNubEmm9j/iFI2tA7W/W+iVoTnDkk0ImcVsVVzOm4Q8EbRJ9N1Lk9y7lo
THaKJaarvku4NL7gdCjUs/V2vd+b/B5+mINt7XvHt8C1STki6lyHO8X2vYVcVZIl
YdabJAm/Ds+3N2/Q7HxKUaxdfCSEFvoGJVEm2xUaUGE7OoZJAyktYjCAm6VDmd8N
7dNiNoLcuxeuw7wxFK2rpBNislL+Jam5wyu86VtX2qgdDXq+yNTHXIWCa+h5YuWa
C33UwCYuuqeSLSDdQCAMaxtKOtt3LGgD2euBsJNBXpVPY0XKkbl0bOpY9fpchaB/
H+NNB+vsAQ7s59i6oKaqqtPOkLx5OXUrJRsdc9c26JrhFxeAb1+OUAWfrxRinlES
OLB70dBCT3BAdaU+iKhnbN2e9eYZw2lduGqmxIUx9MfDHdcf1tU87Mjzi6VswbuW
UxMFIwemMJZsXP2O6dBDKKzSaJooSjRI351SeRTY61otWObY+zerwywaXRc2TkN4
lO2aTh/z7uTMGsUkOj+YXDUweBdFbC2W0GB+aA66nCD/zfAugdM=
=ZGqf
-----END PGP SIGNATURE-----
pgpbRgDYA_moi.pgp
Description: PGP signature
--- End Message ---
--
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel