Cross-family IP Address Parsing Vulnerability in ip-address Library
CVE-2026-101912

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101912?

The ip-address library in JavaScript, prior to version 10.7.1, suffers from a critical vulnerability where the methods isInSubnet and isHostInSubnet fail to properly validate the IP family when comparing masked binary strings. This oversight allows for cross-family containment checks, resulting in security policies potentially misclassifying IP addresses. This flaw can lead to unauthorized access by incorrectly identifying addresses as within safe ranges when they should be outside. Users are urged to upgrade to version 10.7.1 to mitigate this risk.

Affected Version(s)

ip-address < 10.7.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.