Link-Local Address Handling Vulnerability in ip-address Library by Beau Gunderson
CVE-2026-101913
6.3MEDIUM
What is CVE-2026-101913?
The ip-address library, utilized for parsing IPv4 and IPv6 addresses within JavaScript applications, contains a vulnerability that improperly handles the classification of IPv6 link-local addresses. Prior to the 10.5.1 version, the Address6 isLinkLocal method restricted its recognition to the fe80::/64 range, neglecting the broader fe80::/10 link-local scope. This flaw enables an attacker to exploit an address within the complete fe80::/10 range, bypassing trust-boundary checks designed around isLinkLocal. The resultant inconsistency in address categorization can lead to unauthorized access to remote on-link hosts, posing a significant security risk. This vulnerability has been addressed in version 10.5.1.
Affected Version(s)
ip-address < 10.5.1
