Server-side Request Forgery (SSRF) Affecting org.webjars.npm:ip-address package, versions [10.5.0,10.7.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.39% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-20250986
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditRyan Cruz

Introduced: 28 Sep 2026

NewCVE-2026-101910  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade org.webjars.npm:ip-address to version 10.7.0 or higher.

Overview

org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via isPrivate() in src/ipv6.ts, which fails to classify addresses in the RFC 8215 NAT64 local-use range 64:ff9b:1::/48 as private. An attacker who knows or guesses the operator's NAT64 prefix can supply an address in this range that isPrivate() incorrectly reports as globally routable, bypassing any access controls that rely on that check to block internal traffic.

Note: This is only exploitable if the server's network runs a NAT64 translator on a prefix inside 64:ff9b:1::/48 and the attacker knows or can guess the prefix length.

CVSS Base Scores

version 4.0
version 3.1