CVE-2026-101910
Last modified
CVE-2026-101910 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48.
Description
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| beaugunderson | ip-address | >= 10.2.0, < 10.5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-101910?
How severe is CVE-2026-101910?
How do I fix CVE-2026-101910?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-101905Axios is a promise-based HTTP client for the browser and Nod…7.6
- CVE-2026-101906Axios is a promise-based HTTP client for the browser and Nod…8.2
- CVE-2026-101907Axios is a promise-based HTTP client for the browser and Nod…7
- CVE-2026-101908Axios is a promise-based HTTP client for the browser and Nod…6.9
- CVE-2026-101909Axios is a promise-based HTTP client for the browser and Nod…8.3
- CVE-2026-10191A vulnerability was determined in Tenda W12 3.0.0.7(4763). I…8.8
- CVE-2026-101911ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101912ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101913ip-address is a library for parsing and manipulating IPv4 an…6.3
- CVE-2026-101914@grpc/grpc-js implements the core functionality of gRPC pure…6.5
- CVE-2026-101915@grpc/grpc-js implements the core functionality of gRPC pure…3.7
- CVE-2026-10192A vulnerability was identified in Tenda W12 3.0.0.7(4763). T…8.8
Are you affected by CVE-2026-101910?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
