CVE-2026-69192 Details
Description
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.
A vulnerability exists in the ip-address library for JavaScript, specifically in the Address4 component, prior to version 10.3.1. The issue arises because Address4 incorrectly decodes octets with leading zeros as decimal values, while standard URL parsers and network functions interpret them as octal. This discrepancy can lead to misclassification of IP addresses, particularly in the context of server-side request forgery (SSRF) attacks. For example, the address '012.0.0.1' is treated as '12.0.0.1' by the library, but resolves to '10.0.0.1' when fetched, allowing internal targets to be mistakenly classified as external and accessible.
Users can upgrade to ip-address version 10.3.1 or later, where this vulnerability is fixed. If an immediate upgrade is not possible, addresses with leading zeros should be rejected before parsing. After upgrading, 'Address4.isValid('012.0.0.1')' will return false, and the constructor will throw an AddressError.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 3, 2026 | New CVE Received | [email protected] |