CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-101911

CVE-2026-101911: Denial of Service via Uncontrolled Resource Consumption in ip-address Library

Amit Schendel
Amit Schendel
Senior Security Researcher

Sep 30, 2026·7 min read·4 visits

Executive Summary (TL;DR)

The ip-address library prior to 10.7.1 is vulnerable to uncontrolled resource consumption (CWE-400). Unvalidated input length in the Address6 constructor combined with a synchronous HTML-error formatting routine allows unauthenticated remote attackers to trigger severe memory exhaustion or hard process crashes via crafted IP strings.

A denial-of-service vulnerability exists in the ip-address npm package prior to version 10.7.1. The library fails to limit the length of input strings parsed by the Address4 and Address6 constructors. When parsing highly malformed addresses, the diagnostic parser runs a synchronous regular expression search-and-replace that generates descriptive HTML error messages. Passing an excessively long string containing invalid characters causes severe memory amplification and CPU starvation, resulting in a thread hang or process crash in Node.js applications.

Vulnerability Overview

The ip-address package is a widely used Node.js and JavaScript library designed to parse, validate, and manipulate IPv4 and IPv6 addresses. In modern network-facing applications, this library is frequently deployed to inspect client IP addresses extracted from HTTP headers, request bodies, query parameters, or configurations. These endpoints represent a critical attack surface, as they process untrusted input before establishing security policies, checking access control lists, or preventing Server-Side Request Forgery (SSRF).

This vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770 (Allocation of Resources Without Limits or Throttling). Due to the lack of early-stage length bounds on the input string, the parser attempts to process arbitrarily large data streams. This lack of validation exposes application servers to remote, unauthenticated Denial of Service (DoS) attacks.

The core of the threat lies in the synchronous nature of Node.js execution. When an application passes an unvalidated, large payload to the Address6 constructor, the single-threaded event loop becomes completely blocked. The application is unable to process concurrent network requests during this window, leading to widespread performance degradation or complete downtime.

Root Cause Analysis

The root cause of CVE-2026-101911 lies in the internal error-handling and diagnostic logic within the library's address-parsing engine. When an input string is determined to be malformed, the parser does not simply fail-fast. Instead, it attempts to generate an HTML-formatted diagnostic message highlighting the precise syntactic errors within the address.

To identify and highlight illegal characters, the parser executes a synchronous regular expression substitution using constants6.RE_BAD_CHARACTERS (defined as /([^0-9a-f:/%])/gi). For every invalid character encountered in the input, the engine wraps the character inside a verbose HTML span element using address.replace(constants6.RE_BAD_CHARACTERS, '<span class="parse-error">$1</span>').

This substitution introduces an expansion overhead of exactly 34 bytes for every single invalid character (27 bytes for <span class="parse-error"> and 7 bytes for </span>). Because the operation occurs synchronously on Node's single-threaded event loop, processing large strings causes two compounding failure states:

  1. Memory Amplification: JavaScript engines allocate strings in a contiguous memory block. Due to V8's internal UTF-16 representation, garbage collection tracking overhead, and temporary string slice allocations during the substitution loop, the physical memory footprint grows by an amplification factor of approximately 106x compared to the original input size.

  2. CPU Starvation and Engine Failure: At 16 MiB of invalid input, the generated HTML string exceeds V8's maximum allowed string length, throwing a synchronous RangeError. At 32 MiB, the allocation request exceeds contiguous heap boundary limits, forcing the V8 runtime to trigger an uncatchable Fatal JavaScript invalid size error abort, terminating the entire server process.

Code Analysis

To understand the vulnerability and its remediation, we inspect the changes introduced in the codebase. Version 10.7.1 introduces mathematical and logical bounds checks immediately inside the constructors before any string manipulation or regular expression executions occur.

In src/ipv6.ts, the developer established that the longest valid representation of an IPv6 address is 45 characters. This includes the dual IPv4-mapped IPv6 formats (e.g., ffff:ffff:ffff:ffff:ffff:ffff:255.255.255.255). The patch implements a strict length check against this maximum theoretical limit:

// src/ipv6.ts - Patched Implementation
export class Address6 {
  constructor(address: string) {
    // ... pre-processing ...
    
    // The longest well-formed address is all but the last two groups written
    // as four hex digits with their colons, then a 15-character dotted quad:
    // 5 * (groups - 2) + 15, which is 45 for eight groups, the same line
    // CPython's ipaddress module draws. Rejecting longer input here keeps the
    // parse diagnostics, which wrap every offending character in a span,
    // proportional to an address rather than to whatever was passed in.
    const longest = this.groups * 5 + 5; // 8 * 5 + 5 = 45
 
    if (address.length > longest) {
      throw new AddressError(`IPv6 addresses are at most ${longest} characters.`);
    }
 
    this.addressMinusSuffix = address;
    this.parsedAddress = this.parse(this.addressMinusSuffix);
  }
}

Similarly, src/ipv4.ts was patched to prevent memory exhaustion by enforcing a limit of 15 characters (e.g., 255.255.255.255):

// src/ipv4.ts - Patched Implementation
export class Address4 {
  constructor(address: string) {
    // ... pre-processing ...
 
    // Four three-digit octets and three dots: the longest well-formed address
    // is 15 characters. Longer input is rejected before parsing.
    const longest = constants.GROUPS * 4 - 1; // 4 * 4 - 1 = 15
 
    if (address.length > longest) {
      throw new AddressError(`IPv4 addresses are at most ${longest} characters.`);
    }
 
    this.addressMinusSuffix = address;
    this.parsedAddress = this.parse(address);
  }
}

A critical analysis of this patch shows that it successfully mitigates the primary resource amplification path. However, developers must be aware that the length validation check occurs after the initial replacement of zone identifiers (RE_ZONE_STRING) and CIDR subnets. If these pre-processing regex operations are executed against a massively long raw input string, CPU-bound regex overhead could still occur if the raw input is not bounded upstream.

Exploitation Methodology

An attacker can exploit this vulnerability by submitting an excessively long string to any input field that the application parses with ip-address. Common injection vectors include HTTP request headers like X-Forwarded-For or Client-IP, query parameters, or API request fields that accept IP addresses for logging, geolocation, or rate limiting.

The attack vector requires no authentication and can be executed via simple HTTP requests. When the target application invokes new Address6(payload) or Address6.isValid(payload) on the untrusted string, the server event loop blocks.

The following diagram shows the request execution lifecycle and how the resource exhaustion occurs in vulnerable versus patched versions of the library:

In the vulnerable scenario, a payload composed of 16 million non-hexadecimal characters (such as standard exclamation marks or periods) leads to a rapid memory spike and a RangeError. Increasing the payload to 32 MiB results in an uncatchable process-level exception that terminates the Node.js process immediately, bypasses all try-catch constructs, and shuts down the microservice.

Remediation and Mitigation

The primary remediation strategy is upgrading the ip-address dependency to version 10.7.1 or higher. The fixed version introduces early input length validation to prevent execution of the expensive diagnostics subsystem.

In environments where upgrading dependencies immediately is not feasible, application-level defensive mitigations must be implemented to protect the parsing interface:

  1. Implement Early Input Length Filtering: Before passing any string to the ip-address library, enforce an explicit length constraint. No valid IP address representation (including IPv4, IPv6, zone indices, and CIDR masks) requires more than 64 characters. Reject any address strings exceeding this boundary:
function safeParseIP(inputString) {
  if (typeof inputString !== 'string' || inputString.length > 64) {
    throw new Error('Invalid IP address: input exceeds maximum allowable length.');
  }
  return new Address6(inputString);
}
  1. Enforce Global Body Limits: Ensure that web application framework parsing tools (such as the body-parser middleware for Express) enforce low maximum payload limits (e.g., limiting JSON and URL-encoded bodies to less than 100 KiB) to prevent the ingestion of megabyte-scale attack strings.

  2. Use Process Monitoring: Run the Node.js application within a process manager like PM2 or container orchestration systems like Kubernetes. This ensures that even if an unhandled process termination is triggered, the instance is automatically restarted to maintain service availability.

Official Patches

beaugundersonCore Remediation Commit implementing length boundaries on Address4 and Address6.
beaugundersonConsolidation and integration of input-bounds checks.
beaugundersonOfficial release tag v10.7.1 contains the remediation fixes.

Technical Appendix

CVSS Score
6.3/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
EPSS Probability
0.30%
Top 79% most exploited

Affected Systems

Any Node.js or JavaScript application utilizing the 'ip-address' npm library versions prior to 10.7.1.

Affected Versions Detail

Product
Affected Versions
Fixed Version
ip-address
beaugunderson
< 10.7.110.7.1
AttributeDetail
CWE IDCWE-400 / CWE-770
Attack VectorNetwork (AV:N)
CVSS 4.0 Score6.3 (Medium)
EPSS Score0.30% (Percentile: 20.54%)
ImpactDenial of Service (CPU Exhaustion & Process Crash)
Exploit StatusProof-of-Concept
CISA KEV StatusNot Active

MITRE ATT&CK Mapping

T1499Endpoint Denial of Service
Impact
CWE-400
Uncontrolled Resource Consumption

The software is susceptible to resource exhaustion through uncontrolled processing of malformed string inputs.

Vulnerability Timeline

Initial development and dependency assessment begins.
2026-08-29
Implementation of length validation checks for Address4 and Address6.
2026-09-14
Defensive changes merged, tested, and released under tag v10.7.1.
2026-09-15
Official public advisory and CVE-2026-101911 published.
2026-09-28

References & Sources

  • [1]GitHub Security Advisory GHSA-h3mg-xc3c-68pw
  • [2]NVD - CVE-2026-101911
  • [3]CVE.org Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-102278
7.5

CVE-2026-102278: Stack-Based Denial of Service via Uncontrolled Recursion in brace-expansion

A stack-based Denial of Service (DoS) vulnerability via uncontrolled recursion in the brace-expansion library prior to versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11 allows unauthenticated remote attackers to trigger native stack exhaustion, terminating the Node.js process via a crafted payload containing deeply nested brace groups.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 2 hours ago•CVE-2026-102277
5.3

CVE-2026-102277: Denial of Service via Quadratic Algorithmic Complexity in brace-expansion

An uncontrolled resource consumption vulnerability exists in the brace-expansion JavaScript library. Due to an algorithmic flaw in parsing a legacy Bash-compatibility quirk involving {a},b}-shaped expansion structures, untrusted inputs containing many trailing closing braces trigger successive full-input rescans. This behavior yields quadratic CPU time complexity and high memory overhead, allowing remote, unauthenticated attackers to cause a Denial of Service (DoS) by blocking the single-threaded Node.js event loop.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 3 hours ago•CVE-2026-17495
5.9

CVE-2026-17495: Path Traversal via Type Confusion in Moment.js Dynamic Locale Loading

Moment.js versions 2.29.2 through 2.30.1 are vulnerable to a Path Traversal flaw (CWE-27) on server-side Node.js environments when dynamic locales are configured. The vulnerability stems from an object-coercion bypass in the locale-name sanitization routine, which assumes incoming variables are string primitives. An attacker can pass a structured object with custom 'match' and 'toString' properties to bypass regex-based directory checks, leading to arbitrary file loading via Node's internal 'require()' call.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 6 hours ago•CVE-2026-101912
6.3

CVE-2026-101912: Cross-Family IP Address Subnet Containment Logic Bypass in ip-address Library

The ip-address library is vulnerable to a logical bypass in its subnet containment methods. The functions isInSubnet() and isHostInSubnet() do not verify that compared addresses belong to the same IP family before performing masking checks. Under specific circumstances, an IPv6 address can share leading bit patterns with an IPv4 subnet, causing the containment check to evaluate as true. This allows attackers to bypass access control lists, firewalls, and server-side request forgery protection layers in applications relying on the library.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 7 hours ago•CVE-2026-101894
9.1

CVE-2026-101894: Arbitrary File Read/Write via Symbolic Link Chaining in @xhmikosr/decompress

CVE-2026-101894 is a critical path traversal vulnerability in @xhmikosr/decompress before versions 10.2.2 and 11.1.4, stemming from an incomplete hardening bypass of CVE-2026-53486 where static lexical containment checks fail to detect kernel-level resolution of crafted symlink chains, allowing arbitrary local file modification and execution.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 8 hours ago•CVE-2026-86818
4.8

CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri

A security-critical desynchronization vulnerability exists in fast-uri versions 4.1.3 and 4.1.4. Due to incorrect order-of-operations, the mailto scheme parser validates raw percent-encoded parameter keys instead of normalized keys, but subsequently decodes and writes them into a generic headers object. When the parsed URI is serialized, these keys are re-emitted literally, allowing attackers to bypass validation boundaries and smuggle unauthorized recipients, subjects, or body parameters in downstream mailing applications.

Amit Schendel
Amit Schendel
7 views•6 min read