Allocation of Resources Without Limits or Throttling Affecting org.webjars.npm:ip-address package, versions [,10.7.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.3% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-20250984
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditwaydeshi

Introduced: 28 Sep 2026

NewCVE-2026-101911  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade org.webjars.npm:ip-address to version 10.7.2 or higher.

Overview

org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Address6.isValid() method (and the Address4 constructor) when parsing an oversized input string. The bad-character diagnostic wraps every offending character in an HTML <span> element, so an N-byte string of punctuation produces approximately 106N bytes of output and triggers a synchronous String.replace over the entire result. An 8 MiB input takes roughly 529 ms and 895 MB of memory, a 16 MiB input causes a RangeError by exceeding V8's maximum string length, and a 32 MiB input causes V8 to abort the process entirely with a fatal invalid-size error.

Note: Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 or Address4 parsing without an earlier length bound.

CVSS Base Scores

version 4.0
version 3.1