Source: node-ip-address Version: 10.2.0-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-ip-address. CVE-2026-54272[0]: | ip-address is a library for parsing and manipulating IPv4 and IPv6 | addresses in JavaScript. Versions 10.1.1 through 10.2.0 are | vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 | IPv6 addresses. Address6.getType() classifies an address by matching | it against a table of known IPv6 special-use prefixes, returning | Global unicast when nothing matches. That table had no entry for the | IPv4-mapped range (::ffff:0:0/96), so every mapped address fell | through to Global unicast; NAT64 addresses matched their own NAT64 … | labels. The boolean checks isLoopback, isUnspecified, and | isMulticast compared getType() against a fixed label and so returned | false, while isLinkLocal and isULA checked only the native IPv6 | ranges. The library already exposed isMapped4() and to4(), but did | not apply them inside these checks, so a mapped or NAT64 address was | never normalized to its embedded IPv4 address before classification. | For IPv4-mapped addresses the host OS routes to the IPv4 stack, so | the misclassification is reachable on any dual-stack host. For | NAT64, the classification bypass is unconditional but end-to-end | reachability additionally requires a NAT64/DNS64 gateway in the | deployment network.This issue has been fixed in version 10.2.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54272 https://www.cve.org/CVERecord?id=CVE-2026-54272 [1] https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg Regards, Salvatore

