是一个用于在 JavaScript 中解析和操作 IPv4 和 IPv6 地址的库。从版本 10.2.0 到 10.5.1, 中的 类的 分类器未能正确识别 NAT64 本地使用范围 。如果应用程序在信任边界决策中同时使用了 、 和 进行判断,那么通过该 NAT64 范围编码的内部 IPv4 目标地址可能会被错误地视为外部地址。 该漏洞的利用依赖于服务器网络中部署了由运营商选择的、属于本地使用范围内的 NAT64 前缀。成功利用此漏洞可能导致绕过预期的网络信任边界。 此问题已在版本 10.5.1 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| beaugunderson | ip-address | >= 10.2.0, < 10.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| beaugunderson | ip-address | >= 10.2.0, < 10.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101913 | 6.3 MEDIUM | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SS |
| CVE-2026-101911 | 6.3 MEDIUM | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bo |
| CVE-2026-101912 | 6.3 MEDIUM | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as i |
No comments yet