Cross-family IP Address Parsing Vulnerability in ip-address Library
CVE-2026-101912
6.3MEDIUM
What is CVE-2026-101912?
The ip-address library in JavaScript, prior to version 10.7.1, suffers from a critical vulnerability where the methods isInSubnet and isHostInSubnet fail to properly validate the IP family when comparing masked binary strings. This oversight allows for cross-family containment checks, resulting in security policies potentially misclassifying IP addresses. This flaw can lead to unauthorized access by incorrectly identifying addresses as within safe ranges when they should be outside. Users are urged to upgrade to version 10.7.1 to mitigate this risk.
Affected Version(s)
ip-address < 10.7.1
