{"id":"CVE-2026-69198","title":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript","summary":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's ow…","severity":"medium","cwe":["CWE-20","CWE-918"],"vendor":"ip-address","product":"ip-address","affected":["ip-address >= 10.1.1, <= 10.2.1"],"patched":["ip-address 10.2.2"],"published":"2026-08-03","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:30:11.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-69198","references":[{"url":"https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d","label":"security-advisories@github.com"},{"url":"https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2","label":"security-advisories@github.com"},{"url":"https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","label":"security-advisories@github.com"},{"url":"https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-4xrf-jv44-h6hh"}],"tags":["nvd","ghsa","npm"],"epss":0.00414,"epssPercentile":0.3539,"aliases":["GHSA-4xrf-jv44-h6hh"],"ecosystem":"npm","ingestedAt":"2026-08-03T20:29:32.388Z","slug":"CVE-2026-69198","body":"## Overview\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-69198)\n\nAffected packages:\n\n- `ip-address >= 10.1.1, <= 10.2.1`\n\nPatched in:\n\n- `ip-address 10.2.2`\n\nSource: https://github.com/advisories/GHSA-4xrf-jv44-h6hh","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}