chore(deps): update dependency ip-address to ^10.7.1 [security] - autoclosed - #2811
Closed
renovate-bot wants to merge 1 commit into
Closed
renovate-bot wants to merge 1 commit into
renovate-bot wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #2811 +/- ##
=======================================
Coverage 100.0% 100.0%
=======================================
Files 199 199
Lines 25887 25887
Branches 9183 9183
=======================================
Hits 25887 25887
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
angular-slickgrid
aurelia-slickgrid
slickgrid-react
slickgrid-vue
@slickgrid-universal/angular-row-detail-plugin
@slickgrid-universal/aurelia-row-detail-plugin
@slickgrid-universal/react-row-detail-plugin
@slickgrid-universal/vue-row-detail-plugin
@slickgrid-universal/binding
@slickgrid-universal/common
@slickgrid-universal/composite-editor-component
@slickgrid-universal/custom-footer-component
@slickgrid-universal/custom-tooltip-plugin
@slickgrid-universal/empty-warning-component
@slickgrid-universal/event-pub-sub
@slickgrid-universal/excel-export
@slickgrid-universal/graphql
@slickgrid-universal/odata
@slickgrid-universal/pagination-component
@slickgrid-universal/pdf-export
@slickgrid-universal/row-detail-view-plugin
@slickgrid-universal/rxjs-observable
@slickgrid-universal/sql
@slickgrid-universal/text-export
@slickgrid-universal/utils
@slickgrid-universal/vanilla-bundle
@slickgrid-universal/vanilla-force-bundle
@slickgrid-universal/web-mcp
commit: |
renovate-bot
force-pushed
the
renovate/npm-ip-address-vulnerability
branch
from
September 30, 2026 13:32
ed9087c to
0ed8058
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^10.7.0→^10.7.1ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
CVE-2026-101912 / GHSA-j6r3-76f7-8jcv
More information
Details
Summary
isInSubnet()andisHostInSubnet()accept an address of either family and compare masked binary strings without checking that both operands are the same family.Address4pads to 32 bits andAddress6to 128, so whenever the leading bits agree the strings are equal:new Address6('a00::1').isInSubnet(new Address4('10.0.0.0/8'))istrue, andnew Address4('32.0.0.1').isInSubnet(new Address6('2000::/3'))istrue. No IPv4 address is inside an IPv6 network, so both answers are untrue.An application that parses untrusted input as whichever family accepts it and then tests the result against a fixed-family allowlist can admit an address outside the list.
Details
Both methods are in
src/common.ts:mask(n)returns the firstnbits of the address as a string of0and1, taken from a representation padded to the family's width.new Address6('a00::1').mask(8)is'00001010', and so isnew Address4('10.0.0.0/8').mask(), so string equality reports containment. The signature admits either family on either side, so TypeScript raises nothing, and thev4property onAddress6marks IPv4 notation (::ffff:10.0.0.1) rather than family, so it does not discriminate either.Which cross-family pairs coincide depends on the network's prefix length.
mask(n)on anAddress4returns at most 32 bits, so an IPv6 network longer than/32never matches an IPv4 address, and an IPv6 network of/32or shorter matches exactly the IPv4 addresses whose leading bits equal its prefix. An IPv4 network is at most 32 bits and matches every IPv6 address whose leading bits equal its prefix.Affected versions
<= 10.7.0. The comparison has had this shape since the methods were written, so every release is affected.Impact
new Address6('a00::1').isInSubnet(new Address4('10.0.0.0/8'))true00001010new Address4('10.0.0.1').isInSubnet(new Address6('a00::/8'))truenew Address4('32.0.0.1').isInSubnet(new Address6('2000::/3'))true001new Address4('32.1.13.184').isInSubnet(new Address6('2001:db8::/32'))true/32spells an IPv4 addressnew Address6('cb00:7100::1').isInSubnet(new Address4('203.0.113.0/24'))true/24spells an IPv6 prefixnew Address4('10.0.0.1').isInSubnet(new Address6('::ffff:10.0.0.0/104'))false/104is longer than 32 bitsnew Address4('8.8.8.8').isInSubnet(new Address4('10.0.0.0/8'))falseIn the allowlist direction the check admits an address outside the list; in the denylist direction it blocks an address outside the list. What the coincidence can admit is narrow. An IPv6 allowlist of
/32or shorter admits the IPv4 addresses its prefix spells:2001:db8::/32admits exactly32.1.13.184, and2000::/3admits32.0.0.0/3. Those are public IPv4 addresses; the private, loopback, and link-local ranges begin with bit patterns no allocated IPv6 prefix shares. An IPv4 allowlist admits the IPv6 addresses its prefix spells, and those all sit in blocks IANA has not allocated. So a request admitted through this defect reaches an address outside the intended list, not an internal host, and the severity reflects that.Proof of concept
npm i ip-address@10.7.0, then:On affected versions:
The IPv6 rows are right. The IPv4 address whose 32 bits equal the allowlist's prefix is admitted; the one next to it is not.
Remediation
Upgrade to the patched release. In the fix,
isHostInSubnet()returnsfalsewhen the two addresses are of different families, andisInSubnet()inherits the answer. The methods keep accepting either family so existing call sites compile. A caller that means to compare across families converts first, withAddress6.fromAddress4(),to4(), ortoAddress4Nat64():new Address6('::ffff:10.0.0.1').to4().isInSubnet(new Address4('10.0.0.0/8'))istrue, as before.If you cannot upgrade immediately, compare the classes before you compare the addresses:
A note on SSRF defense
These methods are address classifiers, not a complete SSRF defense. Regardless of this fix, a robust SSRF guard must resolve the hostname and validate the resolved IP against the socket it connects to, and account for DNS rebinding and redirects. Treat these checks as one layer, not the only one.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
beaugunderson/ip-address (ip-address)
v10.7.1Compare Source
What's Changed
Full Changelog: beaugunderson/ip-address@v10.7.0...v10.7.1
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.