A vulnerability affecting ip-address versions `<= 10, identified as CVE-2026-101913 with a CVSS score of 6.3, exists in the ip-address library due to an incorrect implementation of Address6.isLinkLocal which recognizes fe80::/64 rather than fe80::/10. This flaw allows Server-Side Request Forgery and trust-boundary bypass to on-link hosts by classifying well-formed addresses in fe80::/10 outside fe80::/64 as untrue, thereby allowing attackers to reach link-local destinations on the server's own segment. The affected version range is <= 10.5.0. This vulnerability can be exploited through a request admitted through a guard built on isLinkLocal, which reaches a link-local host on the server's own segment. The severity of this flaw reflects that the reach is limited to the server's own segment rather than the internet or a universal metadata endpoint, making it a medium-severity issue.
We recommend you to update ip-address to version 10.5.1.[/subscribe_to_unlock_form]
A vulnerability affecting ip-address versions `<= 10, identified as CVE-2026-101913 with a CVSS score of 6.3, exists in the ip-address library due to an incorrect implementation of Address6.isLinkLocal which recognizes fe80::/64 rather than fe80::/10. This flaw allows Server-Side Request Forgery and trust-boundary bypass to on-link hosts by classifying well-formed addresses in fe80::/10 outside fe80::/64 as untrue, thereby allowing attackers to reach link-local destinations on the server's own segment. The affected version range is <= 10.5.0. This vulnerability can be exploited through a request admitted through a guard built on isLinkLocal, which reaches a link-local host on the server's own segment. The severity of this flaw reflects that the reach is limited to the server's own segment rather than the internet or a universal metadata endpoint, making it a medium-severity issue.
We recommend you to update ip-address to version 10.5.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]