Unbounded String Processing in ip-address Library by Beau Gunderson
CVE-2026-101911
6.3MEDIUM
What is CVE-2026-101911?
The ip-address library, utilized for manipulating IPv4 and IPv6 addresses in JavaScript, has a vulnerability that affects versions prior to 10.7.1. Specifically, the Address6 constructor and the Address6.isValid function allow unbounded strings, which can lead to large memory consumption and potential application stalls when handling attacker-controlled inputs. This vulnerability manifests when large invalid inputs are parsed, leading to significant performance issues, including synchronous stalls and memory exceptions. The problem is mitigated in version 10.7.1, where proper length checks have been implemented to protect applications from extensive input sizes.
Affected Version(s)
ip-address < 10.7.1
