PT-2026-99954 · Npm · Ipaddress
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ip-address versions prior to 10.7.1
Description
The
Address6 constructor, Address6.isValid function, and the parse code in src/ipv6.ts accept unbounded strings. When invalid characters are processed through RE BAD CHARACTERS, they are expanded into large diagnostics. This can lead to a synchronous stall and high transient memory usage when processing megabyte-scale fields. Specifically, fields of approximately 16 MiB can trigger an invalid string length exception, and fields of approximately 32 MiB can cause process termination. This occurs when an application passes a very large attacker-controlled field to the parsing logic without a prior length bound.Recommendations
Update to version 10.7.1.
As a temporary mitigation, implement a length bound on input fields before passing them to
Address6.isValid or the Address6 constructor.Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipaddress