Parsing and Manipulating IPv4 and IPv6 Address Library Vulnerability in ip-address by Beaugunderson
CVE-2026-69192

7.7HIGH

Key Information:

Vendor
CVE Published:
3 August 2026

What is CVE-2026-69192?

The ip-address library prior to version 10.3.1 has a vulnerability where leading zeros in octets are improperly interpreted. This discrepancy between Address4 and the network stack could lead to security issues, such as misclassifying internal addresses as external ones. For instance, '012.0.0.1' resolves to a different IP address than intended. This flaw affects several methods used to determine address types, potentially allowing unauthorized network requests, which may compromise system integrity. The library has been updated to address this parsing inconsistency.

Affected Version(s)

ip-address < 10.3.1

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.