Incorrect Comparison in ip-address - #VU146515

 

Incorrect Comparison in ip-address - #VU146515

Published: August 31, 2026


Vulnerability identifier: #VU146515
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-697
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass network trust boundaries and perform server-side request forgery against on-link hosts.

The vulnerability exists due to incorrect comparison in Address6.isLinkLocal() in src/ipv6.ts when classifying IPv6 link-local addresses. A remote attacker can supply a crafted link-local IPv6 address outside fe80::/64 but within fe80::/10 to bypass network trust boundaries and perform server-side request forgery against on-link hosts.

The issue affects applications that rely on this method for security decisions, and reachable targets are generally limited to hosts on the server\'s own network segment.


Affected software

ip-address

Remediation

Install security update from vendor's website.

ip-address - update to 10.5.1

External References

Related Security Bulletins