๐Ÿ” CVE Alert

CVE-2026-69192

UNKNOWN 0.0

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.

CWE CWE-20 CWE-918
Vendor beaugunderson
Product ip-address
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for beaugunderson ip-address

Be the first to know when new unknown vulnerabilities affecting beaugunderson ip-address are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

beaugunderson / ip-address
< 10.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr github.com: https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e github.com: https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1