是一个用于在 JavaScript 中解析和操作 IPv4 和 IPv6 地址的库。在版本 10.7.1 之前, 中的 和 方法在比较掩码后的二进制字符串时,未验证两个操作数是否使用相同的 IP 地址族(IP family)。当进行跨地址族的包含关系检查且前导地址位匹配时,即使 IPv4 和 IPv6 并不共享地址空间,掩码后的字符串仍可能比较为相等。因此,基于白名单或黑名单的决策可能错误地将本不在预期范围内的地址判定为包含在内。该问题已在版本 10.7.1 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| beaugunderson | ip-address | < 10.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| beaugunderson | ip-address | < 10.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101910 | 6.9 MEDIUM | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SS |
| CVE-2026-101913 | 6.3 MEDIUM | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SS |
| CVE-2026-101911 | 6.3 MEDIUM | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bo |
No comments yet