CVE-2026-101911
Received Received - Intake

Denial of Service in ip-address Library via Unbounded String Parsing

Vulnerability report for CVE-2026-101911, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
beaugunderson ip-address to 10.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ip-address JavaScript library before version 10.7.1. It involves the Address6 constructor and parsing functions not enforcing input length limits. When processing very large attacker-controlled strings, the library consumes excessive memory and CPU, leading to performance degradation or crashes. The issue occurs when applications accept large untrusted input and pass it to Address6 parsing without prior length validation.

Detection Guidance

Check if your application uses ip-address library versions 10.7.0 or earlier. Monitor for high memory usage or process stalls when parsing IPv6 addresses. Use input validation to limit IPv6 strings to 45 characters and IPv4 to 15 characters before parsing.

Impact Analysis

An attacker could send a large malicious string to an application using the vulnerable library, causing high memory usage and CPU consumption. This may lead to application slowdowns, crashes, or denial-of-service conditions. For example, a 32 MiB input could terminate the Node.js process entirely.

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by consuming excessive memory and CPU resources when processing maliciously long input strings. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA compliance. However, prolonged service disruptions could impact availability requirements under these standards.

Mitigation Strategies

Upgrade to ip-address version 10.7.1 or later. Implement input length checks to reject IPv6 strings longer than 45 characters and IPv4 strings longer than 15 characters before parsing. Use body-parser defaults to limit request sizes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101911. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart