Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-j6r3-76f7-8jcv
  • npm/ip-address
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range 5 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-h3mg-xc3c-68pw
  • npm/ip-address
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process 5 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-rpw4-54j3-4h4q
  • npm/ip-address
ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts 6 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-2vr4-cq9g-pvrc
  • npm/ip-address
ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass 6 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-mwp4-54f8-5fhr
  • npm/ip-address
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass 03 Aug
  • Fix available
  • Severity - 7.7 (High)
GHSA-4xrf-jv44-h6hh
  • npm/ip-address
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks 03 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-22jq-vg5j-6vgg
  • npm/ip-address
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks 03 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-v2v4-37r5-5v8g
  • npm/ip-address
ip-address has XSS in Address6 HTML-emitting methods 05 May
  • Fix available
  • Severity - 5.3 (Medium)