PT-2026-99954 · Npm · Ipaddress

·

CVE-2026-101911

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ip-address versions prior to 10.7.1
Description The Address6 constructor, Address6.isValid function, and the parse code in src/ipv6.ts accept unbounded strings. When invalid characters are processed through RE BAD CHARACTERS, they are expanded into large diagnostics. This can lead to a synchronous stall and high transient memory usage when processing megabyte-scale fields. Specifically, fields of approximately 16 MiB can trigger an invalid string length exception, and fields of approximately 32 MiB can cause process termination. This occurs when an application passes a very large attacker-controlled field to the parsing logic without a prior length bound.
Recommendations Update to version 10.7.1. As a temporary mitigation, implement a length bound on input fields before passing them to Address6.isValid or the Address6 constructor.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101911
GHSA-H3MG-XC3C-68PW

Affected Products

Ipaddress