CVE-2026-101910
Received Received - Intake

ip-address Library NAT64 Local-Use Range Bypass

Vulnerability report for CVE-2026-101910, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
beaugunderson ip-address From 10.2.0 (inc) to 10.5.1 (exc)
beaugunderson ip-address 10.5.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the ip-address library (versions 10.2.0 to 10.5.0) involves the Address6.isPrivate classifier not recognizing the NAT64 local-use range 64:ff9b:1::/48. This causes internal IPv4 addresses encoded through this range to be treated as external, bypassing trust boundaries. The issue is fixed in version 10.5.1.

Detection Guidance

Check if your application uses ip-address library versions 10.2.0 to 10.5.0. Run npm list ip-address to verify the installed version. If vulnerable, update to 10.5.1 or later. Test IPv6 addresses in the NAT64 range 64:ff9b:1::/48 to confirm they are incorrectly classified as non-private.

Impact Analysis

This vulnerability can allow Server-Side Request Forgery (SSRF) attacks and trust-boundary bypasses. Internal IPv4 destinations mapped via NAT64 prefixes may be incorrectly classified as global addresses, bypassing security filters designed to block SSRF. Exploitation requires a NAT64 translator using a custom prefix within 64:ff9b:1::/48.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling SSRF attacks that bypass network trust boundaries. If an application incorrectly treats internal NAT64-mapped addresses as external, it may fail to enforce proper access controls for sensitive data, violating principles of least privilege and network segmentation required by these regulations.

Mitigation Strategies

Upgrade the ip-address library to version 10.5.1 or later. If upgrading is not possible, implement additional SSRF defenses such as network-level filtering or input validation for IPv6 addresses. Review applications using isPrivate(), isLoopback(), or isLinkLocal() for trust-boundary decisions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101910. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart