是一个用于在 JavaScript 中解析和操作 IPv4 和 IPv6 地址的库。在版本 10.5.1 之前, 中的 方法仅识别 ,而未识别完整的 IPv6 链路本地地址范围。因此,攻击者控制的、位于 范围内的其他地址可能通过依赖 的信任边界检查。同时, 和 方法也将该地址识别为链路本地地址,导致分类结果不一致。成功绕过该检查后,攻击者可能访问到超出预期信任边界的链上主机。此问题已在版本 10.5.1 中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| beaugunderson | ip-address | < 10.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| beaugunderson | ip-address | < 10.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101910 | 6.9 MEDIUM | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SS |
| CVE-2026-101911 | 6.3 MEDIUM | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bo |
| CVE-2026-101912 | 6.3 MEDIUM | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as i |
No comments yet