ip-address
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ip-addresspage 1 of 1
- CVE-2026-42338MEDIUMCVSS 6.1EG 6.1✓ Fixed in 10.1.12026-05-12
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they r…
- CVE-2026-54272MEDIUMCVSS 6.9EG 6.9✓ Fixed in 10.2.12026-07-27
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies …
- CVE-2026-69192HIGHCVSS 7.7EG 7.7✓ Fixed in 10.3.12026-08-03
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and …
- CVE-2026-69198MEDIUMCVSS 6.9EG 6.9✓ Fixed in 10.2.22026-08-03
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own …
Check whether ip-address is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ip-address CVEs against the assets you own.
Start Free Scan →