AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101912.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Summary `isInSubnet()` and `isHostInSubnet()` accept an address of either family and compare masked binary strings without checking that both operands are the same family. `Address4` pads to 32 bits and `Address6` to 128, so whenever the leading bits agree the strings are equal: `new Address6('a00::1').isInSubnet(new Address4('10.0.0.0/8'))` is `true`, and `new Address4('32.0.0.1').isInSubnet(new Address6('2000::/3'))` is `true`. No IPv4 address is inside an IPv6 network, so both answers are untrue. An application that parses untrusted input as whichever family accepts it and then tests the result against a fixed-family allowlist can admit an address outside the list. ### Details Both methods are in `src/common.ts`: ```ts export function isInSubnet(this: Address4 | Address6, address: Address4 | Address6) { if (this.subnetMask < address.subnetMask) { return false; } return isHostInSubnet.call(this, address); } export function isHostInSubnet(this: Address4 | Address6, address: Address4 | Address6) { return this.mask(address.subnetMask) === address.mask(); } ``` `mask(n)` returns the first `n` bits of the address as a string of `0` and `1`, taken from a representation padded to th

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-j6r3-76f7-8jcv

Open original source · Updated Sep 29, 2026

ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range

Source severity: MEDIUM / 6.3

EcosystemPackageAffected rangeFirst patched
npmip-address10.7.1

Original records & references

PUBLISHED 2026-09-29T19:46:52-04:00
MODIFIED 2026-09-29T19:46:54-04:00
INGESTED 2026-10-06T11:43:09-04:00