CVE-2026-42338General(beaugunderson / ip-address)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch beaugunderson ip-address systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ip-address

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
ip-address

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 105-12
Signal classification1 categories
General
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • CVE@CVEnew
    General

    CVE-2026-42338 ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, http://Address6.group() and http://Address6.link() do not HTML-escape a… https://www.cve.org/CVERecord?id=CVE-2026-42338

    Post summary

    CVE-2026-42338 is a vulnerability in the ip-address library where certain functions lack HTML escaping, with a fix implied in version 10.1.1; no proof of concept, exploit, or active exploitation is mentioned.

    00000127
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbeaugundersonip-address-node.js-

Explore more