Disclosure summary
### Summary `isInSubnet()` and `isHostInSubnet()` accept an address of either family and compare masked binary strings without checking that both operands are the same family. `Address4` pads to 32 bits and `Address6` to 128, so whenever the leading bits agree the strings are equal: `new Address6('a00::1').isInSubnet(new Address4('10.0.0.0/8'))` is `true`, and `new Address4('32.0.0.1').isInSubnet(new Address6('2000::/3'))` is `true`. No IPv4 address is inside an IPv6 network, so both answers are untrue. An application that parses untrusted input as whichever family accepts it and then tests the result against a fixed-family allowlist can admit an address outside the list. ### Details Both methods are in `src/common.ts`: ```ts export function isInSubnet(this: Address4 | Address6, address: Address4 | Address6) { if (this.subnetMask < address.subnetMask) { return false; } return isHostInSubnet.call(this, address); } export function isHostInSubnet(this: Address4 | Address6, address: Address4 | Address6) { return this.mask(address.subnetMask) === address.mask(); } ``` `mask(n)` returns the first `n` bits of the address as a string of `0` and `1`, taken from a representation padded to th
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-j6r3-76f7-8jcv
Open original source · Updated Sep 29, 2026
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
Source severity: MEDIUM / 6.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | ip-address | 10.7.1 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T19:46:52-04:00
MODIFIED 2026-09-29T19:46:54-04:00
INGESTED 2026-10-06T11:43:09-04:00