Link-Local Address Handling Vulnerability in ip-address Library by Beau Gunderson
CVE-2026-101913

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101913?

The ip-address library, utilized for parsing IPv4 and IPv6 addresses within JavaScript applications, contains a vulnerability that improperly handles the classification of IPv6 link-local addresses. Prior to the 10.5.1 version, the Address6 isLinkLocal method restricted its recognition to the fe80::/64 range, neglecting the broader fe80::/10 link-local scope. This flaw enables an attacker to exploit an address within the complete fe80::/10 range, bypassing trust-boundary checks designed around isLinkLocal. The resultant inconsistency in address categorization can lead to unauthorized access to remote on-link hosts, posing a significant security risk. This vulnerability has been addressed in version 10.5.1.

Affected Version(s)

ip-address < 10.5.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.