Unbounded String Processing in ip-address Library by Beau Gunderson
CVE-2026-101911

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101911?

The ip-address library, utilized for manipulating IPv4 and IPv6 addresses in JavaScript, has a vulnerability that affects versions prior to 10.7.1. Specifically, the Address6 constructor and the Address6.isValid function allow unbounded strings, which can lead to large memory consumption and potential application stalls when handling attacker-controlled inputs. This vulnerability manifests when large invalid inputs are parsed, leading to significant performance issues, including synchronous stalls and memory exceptions. The problem is mitigated in version 10.7.1, where proper length checks have been implemented to protect applications from extensive input sizes.

Affected Version(s)

ip-address < 10.7.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.