๐Ÿ” CVE Alert

CVE-2026-42338

HIGH 8.1

ip-address: XSS in Address6 HTML-emitting methods

CVSS Score
8.1
EPSS Score
0.5%
EPSS Percentile
38th

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CWE CWE-79
Vendor beaugunderson
Product ip-address
Published May 12, 2026
Last Updated Jul 13, 2026
Stay Ahead of the Next One

Get instant alerts for beaugunderson ip-address

Be the first to know when new high vulnerabilities affecting beaugunderson ip-address are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

beaugunderson / ip-address
< 10.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-42338 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2476810 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35842 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35841 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35892 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35891 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:34374 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:36754 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33574 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:36820 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33155 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33163 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33173 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33183 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33160