CVE-2026-101911 ip-address 正则表达式拒绝服务漏洞
影响超大输入可致服务同步阻塞、内存激增甚至进程终止
ip-address 是 JavaScript 中用于解析和操作 IPv4/IPv6 地址的库。10.7.1 之前,Address6 构造函数、Address6.isValid 及相关解析代码接受无长度限制的字符串,并将非法字符展开为大量诊断信息。当应用把超大攻击者可控字段直接传入解析时,可能造成拒绝服务。
影响范围
ip-address 10.7.1 之前的版本,涉及 Address6 构造函数、Address6.isValid 及进入 parse 的构造路径。
漏洞详情
该漏洞属于无界输入导致的资源耗尽类问题。解析代码未先限制输入长度,遇到超大字符串时会同步展开非法字符诊断,造成阻塞和高内存占用。约 16 MiB 输入可触发无效字符串长度异常,约 32 MiB 时可导致进程终止。
利用条件与风险
利用前提是应用接受超大攻击者可控字段并直接交给 Address6 解析且无前置长度限制。常见 URL、请求头限制及 body-parser 默认值通常会约束影响,实战风险中等。
修复建议
升级到 ip-address 10.7.1 或更高版本;临时缓解措施是在调用解析前对输入长度设置上限,并配置合理的请求体大小限制。
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1.