- Package:
- src:node-ip-address
- Source:
- src:node-ip-address
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-30 13:21:06 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-ip-address. CVE-2026-54272[0]: | ip-address is a library for parsing and manipulating IPv4 and IPv6 | addresses in JavaScript. Versions 10.1.1 through 10.2.0 are | vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 | IPv6 addresses. Address6.getType() classifies an address by matching | it against a table of known IPv6 special-use prefixes, returning | Global unicast when nothing matches. That table had no entry for the | IPv4-mapped range (::ffff:0:0/96), so every mapped address fell | through to Global unicast; NAT64 addresses matched their own NAT64 … | labels. The boolean checks isLoopback, isUnspecified, and | isMulticast compared getType() against a fixed label and so returned | false, while isLinkLocal and isULA checked only the native IPv6 | ranges. The library already exposed isMapped4() and to4(), but did | not apply them inside these checks, so a mapped or NAT64 address was | never normalized to its embedded IPv4 address before classification. | For IPv4-mapped addresses the host OS routes to the IPv4 stack, so | the misclassification is reachable on any dual-stack host. For | NAT64, the classification bypass is unconditional but end-to-end | reachability additionally requires a NAT64/DNS64 gateway in the | deployment network.This issue has been fixed in version 10.2.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54272 https://www.cve.org/CVERecord?id=CVE-2026-54272 [1] https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg Regards, Salvatore
Hello, Bug #1143057 in node-ip-address reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-ip-address/-/commit/74dc808e07198abe77bc0260164c1538d72cda23 (this message was generated automatically) -- Greetings https://bugs.debian.org/1143057
Hello, Bug #1143057 in node-ip-address reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-ip-address/-/commit/74dc808e07198abe77bc0260164c1538d72cda23 (this message was generated automatically) -- Greetings https://bugs.debian.org/1143057
We believe that the bug you reported is fixed in the latest version of node-ip-address, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1143057@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-ip-address package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Thu, 30 Jul 2026 14:54:55 +0200 Source: node-ip-address Architecture: source Version: 10.3.1-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1143057 Changes: node-ip-address (10.3.1-1) unstable; urgency=medium . * Team upload * New upstream version (Closes: #1143057, CVE-2026-54272) Checksums-Sha1: a57f9f1cba3c8562bfe13f5c4543f03910ac96ba 2194 node-ip-address_10.3.1-1.dsc 8e10371605d378aa74435c27ee77fd61c1380565 110215 node-ip-address_10.3.1.orig.tar.gz 4e15fb99ce188bb70867a826f4582e8da61d507c 3276 node-ip-address_10.3.1-1.debian.tar.xz Checksums-Sha256: fd8e4c2ecdda20bdf290e922b68bc821cc5241f6b82130ea664f43c29167e324 2194 node-ip-address_10.3.1-1.dsc d8147d926dcbdbe71956b350d2d84373836a87e9b48664e7cbb7b5c8b6e5a36b 110215 node-ip-address_10.3.1.orig.tar.gz 0918d8130eb14eeb59c4ed86afa78dc035492faff6997fee2b4762bf2e402e8c 3276 node-ip-address_10.3.1-1.debian.tar.xz Files: dffd22293188e3d53446926ae7816ab0 2194 javascript optional node-ip-address_10.3.1-1.dsc 124b104aaec8b01bab081b1588b528e9 110215 javascript optional node-ip-address_10.3.1.orig.tar.gz bd62dca23981a75dfdaf2f6a2cdc0b1c 3276 javascript optional node-ip-address_10.3.1-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprSd4ACgkQ9tdMp8mZ 7unObQ//cgfIJITCw/imiZSTByBspsFz3zWurEZskxrYg3Y+WCzhz5WdnquZJ2Z6 3N92JscTUncW6pL0l7MoJXEvNFRU4ejYlH3RTcCaw3RHM3c+40lqeulm7/YiviOd MvqbefVPNubEmm9j/iFI2tA7W/W+iVoTnDkk0ImcVsVVzOm4Q8EbRJ9N1Lk9y7lo THaKJaarvku4NL7gdCjUs/V2vd+b/B5+mINt7XvHt8C1STki6lyHO8X2vYVcVZIl YdabJAm/Ds+3N2/Q7HxKUaxdfCSEFvoGJVEm2xUaUGE7OoZJAyktYjCAm6VDmd8N 7dNiNoLcuxeuw7wxFK2rpBNislL+Jam5wyu86VtX2qgdDXq+yNTHXIWCa+h5YuWa C33UwCYuuqeSLSDdQCAMaxtKOtt3LGgD2euBsJNBXpVPY0XKkbl0bOpY9fpchaB/ H+NNB+vsAQ7s59i6oKaqqtPOkLx5OXUrJRsdc9c26JrhFxeAb1+OUAWfrxRinlES OLB70dBCT3BAdaU+iKhnbN2e9eYZw2lduGqmxIUx9MfDHdcf1tU87Mjzi6VswbuW UxMFIwemMJZsXP2O6dBDKKzSaJooSjRI351SeRTY61otWObY+zerwywaXRc2TkN4 lO2aTh/z7uTMGsUkOj+YXDUweBdFbC2W0GB+aA66nCD/zfAugdM= =ZGqf -----END PGP SIGNATURE-----