CVE-2026-101912

Source
https://cve.org/CVERecord?id=CVE-2026-101912
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101912.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-101912
Aliases
Downstream
Published
2026-09-28T17:48:06Z
Modified
2026-09-30T03:47:04Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Details

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-697",
        "CWE-843"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101912.json"
}
References

Affected packages

Git / github.com/beaugunderson/ip-address

Affected ranges

Type
GIT
Repo
https://github.com/beaugunderson/ip-address
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "10.7.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0
1.1.0
2.*
2.0.0
v10.*
v10.0.0
v10.0.1
v10.1.0
v10.1.1
v10.2.0
v10.2.1
v10.2.2
v10.3.0
v10.3.1
v10.4.0
v10.5.0
v10.5.1
v10.6.0
v10.7.0
v2.*
v2.0.1
v2.0.2
v3.*
v3.1.0
v5.*
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
v5.6.0
v5.7.0
v5.8.0
v5.8.1
v5.8.2
v5.8.3
v5.8.4
v5.8.5
v5.8.6
v5.8.7
v5.8.8
v5.8.9
v5.9.0
v5.9.1
v5.9.2
v5.9.3
v5.9.4
v6.*
v6.0.0
v6.1.0
v6.2.0
v6.3.0
v6.4.0
v7.*
v7.0.0
v7.0.1
v7.1.0
v8.*
v8.0.0
v8.1.0
v9.*
v9.0.0
v9.0.1
v9.0.2
v9.0.3
v9.0.5
v9.1.0-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101912.json"