Improper Validation of Specified Type of Input Affecting org.webjars.npm:ip-address package, versions [,10.7.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.37% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-20250963
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditwaydeshi

Introduced: 28 Sep 2026

NewCVE-2026-101912  (opens in a new tab)
CWE-1287  (opens in a new tab)

How to fix?

Upgrade org.webjars.npm:ip-address to version 10.7.2 or higher.

Overview

org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.

Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input via isHostInSubnet() (and isInSubnet() which delegates to it), which compares masked binary strings without first verifying that both addresses belong to the same address family. Because Address4 pads its binary representation to 32 bits and Address6 pads to 128 bits, leading bit sequences can coincide across families, causing an IPv6 address to be incorrectly reported as contained within an IPv4 subnet and vice versa (for example, a00::1 is evaluated as inside 10.0.0.0/8). An attacker who controls an IP address value passed to a subnet membership check can bypass trust-boundary decisions such as SSRF allow/deny filters by supplying an address of the opposite family.

CVSS Base Scores

version 4.0
version 3.1