Allocation of Resources Without Limits or Throttling in ip-address - #VU150201
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits in the Address6 parse diagnostic generation when processing oversized invalid IPv6 address strings. A remote attacker can submit a specially crafted oversized address string to cause a denial of service.
Address6.isValid() constructs the diagnostic before discarding it.