CVE-2026-101912
Received Received - Intake

IPv4/IPv6 Subnet Check Bypass in ip-address Library

Vulnerability report for CVE-2026-101912, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
beaugunderson ip-address to 10.7.1 (exc)
beaugunderson ip-address 10.7.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CWE-697 The product compares two entities in a security-relevant context, but the comparison is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ip-address JavaScript library before version 10.7.1. The isInSubnet and isHostInSubnet methods incorrectly compare IPv4 and IPv6 addresses as if they shared the same address space. By comparing masked binary strings without validating IP family compatibility, the methods can falsely identify an address from one family as belonging to a subnet of another family. For example, an IPv6 address might incorrectly match an IPv4 subnet if their leading bits align after padding to 32 or 128 bits respectively.

Detection Guidance

To detect this vulnerability, check if your system uses ip-address library versions 10.7.0 or earlier. Run: npm list ip-address. If version is <=10.7.0, the system is vulnerable. Also review code using isInSubnet or isHostInSubnet methods for cross-family comparisons.

Impact Analysis

This vulnerability could allow an attacker to bypass IP-based allowlist or denylist restrictions. If your application uses these methods to validate IP addresses against subnets, an attacker might craft an input that appears to belong to an allowed subnet but is actually from a different IP family. This could lead to unauthorized access or data exposure, especially if the application relies solely on these methods for security checks.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized IP addresses to bypass allowlist or denylist restrictions. If an application uses this library to validate IP addresses for access control, an attacker might craft an IP address that incorrectly matches a permitted subnet, leading to unauthorized access to sensitive data or systems. This could violate data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., unauthorized access to protected health information).

Mitigation Strategies

Upgrade the ip-address library to version 10.7.1 or later using: npm update ip-address. As a temporary measure, add validation to ensure IP families match before calling subnet methods.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101912. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart