#1143057 node-ip-address: CVE-2026-54272

Package:
src:node-ip-address
Source:
src:node-ip-address
Submitter:
Salvatore Bonaccorso
Date:
2026-07-30 13:21:06 UTC
Severity:
normal
Tags:
#1143057#5
Date:
2026-07-30 04:47:36 UTC
From:
To:
Hi,

The following vulnerability was published for node-ip-address.

CVE-2026-54272[0]:
| ip-address is a library for parsing and manipulating IPv4 and IPv6
| addresses in JavaScript. Versions 10.1.1 through 10.2.0 are
| vulnerable to SSRF through misclassification of IPv4-mapped/NAT64
| IPv6 addresses. Address6.getType() classifies an address by matching
| it against a table of known IPv6 special-use prefixes, returning
| Global unicast when nothing matches. That table had no entry for the
| IPv4-mapped range (::ffff:0:0/96), so every mapped address fell
| through to Global unicast; NAT64 addresses matched their own NAT64 …
| labels. The boolean checks isLoopback, isUnspecified, and
| isMulticast compared getType() against a fixed label and so returned
| false, while isLinkLocal and isULA checked only the native IPv6
| ranges. The library already exposed isMapped4() and to4(), but did
| not apply them inside these checks, so a mapped or NAT64 address was
| never normalized to its embedded IPv4 address before classification.
| For IPv4-mapped addresses the host OS routes to the IPv4 stack, so
| the misclassification is reachable on any dual-stack host. For
| NAT64, the classification bypass is unconditional but end-to-end
| reachability additionally requires a NAT64/DNS64 gateway in the
| deployment network.This issue has been fixed in version 10.2.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54272
https://www.cve.org/CVERecord?id=CVE-2026-54272
[1] https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg

Regards,
Salvatore

#1143057#8
Date:
2026-07-30 12:56:37 UTC
From:
To:
Hello,

Bug #1143057 in node-ip-address reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-ip-address/-/commit/74dc808e07198abe77bc0260164c1538d72cda23

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143057

#1143057#13
Date:
2026-07-30 12:56:39 UTC
From:
To:
Hello,

Bug #1143057 in node-ip-address reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-ip-address/-/commit/74dc808e07198abe77bc0260164c1538d72cda23

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143057

#1143057#18
Date:
2026-07-30 13:19:57 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-ip-address, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143057@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-ip-address package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 30 Jul 2026 14:54:55 +0200
Source: node-ip-address
Architecture: source
Version: 10.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1143057
Changes:
 node-ip-address (10.3.1-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version (Closes: #1143057, CVE-2026-54272)
Checksums-Sha1:
 a57f9f1cba3c8562bfe13f5c4543f03910ac96ba 2194 node-ip-address_10.3.1-1.dsc
 8e10371605d378aa74435c27ee77fd61c1380565 110215 node-ip-address_10.3.1.orig.tar.gz
 4e15fb99ce188bb70867a826f4582e8da61d507c 3276 node-ip-address_10.3.1-1.debian.tar.xz
Checksums-Sha256:
 fd8e4c2ecdda20bdf290e922b68bc821cc5241f6b82130ea664f43c29167e324 2194 node-ip-address_10.3.1-1.dsc
 d8147d926dcbdbe71956b350d2d84373836a87e9b48664e7cbb7b5c8b6e5a36b 110215 node-ip-address_10.3.1.orig.tar.gz
 0918d8130eb14eeb59c4ed86afa78dc035492faff6997fee2b4762bf2e402e8c 3276 node-ip-address_10.3.1-1.debian.tar.xz
Files:
 dffd22293188e3d53446926ae7816ab0 2194 javascript optional node-ip-address_10.3.1-1.dsc
 124b104aaec8b01bab081b1588b528e9 110215 javascript optional node-ip-address_10.3.1.orig.tar.gz
 bd62dca23981a75dfdaf2f6a2cdc0b1c 3276 javascript optional node-ip-address_10.3.1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmprSd4ACgkQ9tdMp8mZ
7unObQ//cgfIJITCw/imiZSTByBspsFz3zWurEZskxrYg3Y+WCzhz5WdnquZJ2Z6
3N92JscTUncW6pL0l7MoJXEvNFRU4ejYlH3RTcCaw3RHM3c+40lqeulm7/YiviOd
MvqbefVPNubEmm9j/iFI2tA7W/W+iVoTnDkk0ImcVsVVzOm4Q8EbRJ9N1Lk9y7lo
THaKJaarvku4NL7gdCjUs/V2vd+b/B5+mINt7XvHt8C1STki6lyHO8X2vYVcVZIl
YdabJAm/Ds+3N2/Q7HxKUaxdfCSEFvoGJVEm2xUaUGE7OoZJAyktYjCAm6VDmd8N
7dNiNoLcuxeuw7wxFK2rpBNislL+Jam5wyu86VtX2qgdDXq+yNTHXIWCa+h5YuWa
C33UwCYuuqeSLSDdQCAMaxtKOtt3LGgD2euBsJNBXpVPY0XKkbl0bOpY9fpchaB/
H+NNB+vsAQ7s59i6oKaqqtPOkLx5OXUrJRsdc9c26JrhFxeAb1+OUAWfrxRinlES
OLB70dBCT3BAdaU+iKhnbN2e9eYZw2lduGqmxIUx9MfDHdcf1tU87Mjzi6VswbuW
UxMFIwemMJZsXP2O6dBDKKzSaJooSjRI351SeRTY61otWObY+zerwywaXRc2TkN4
lO2aTh/z7uTMGsUkOj+YXDUweBdFbC2W0GB+aA66nCD/zfAugdM=
=ZGqf
-----END PGP SIGNATURE-----