SCA: security update for ip-address (GHSA-4xrf-jv44-h6hh)

medium Tenable Self-Hosted Container Security Plugin ID 445597

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1
until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to
false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes
verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses
classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(),
isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable,
while correctForm() and address still return the real internal target. An application that builds a
network trust-boundary decision on these checks, for example a filter intended to block Server-Side
Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The
underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed
address independently of subnetMask; the defect is solely that the containment guard sits in the
classification path. This issue is fixed in version 10.2.2. (CVE-2026-69198)

Solution

Update the ip-address library and its related packages to version 10.2.2 or later.

See Also

https://github.com/advisories/GHSA-4xrf-jv44-h6hh

Plugin Details

Severity: Medium

ID: 445597

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/4/2026

Updated: 8/4/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-69198

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/3/2026

Vulnerability Publication Date: 8/3/2026

Reference Information

CVE: CVE-2026-69198