CVE-2026-101910 ip-address 信任边界绕过漏洞
影响可绕过网络信任边界,将内部地址误判为外部
ip-address 是一个用于解析和操作 IPv4/IPv6 地址的 JavaScript 库。其 Address6 的 isPrivate 分类器未识别 NAT64 本地使用范围 64:ff9b:1::/48,导致依赖该判断做信任边界决策的应用可能将内部 IPv4 目标误判为外部。该问题已在 10.5.1 版本修复。
影响范围
ip-address 10.2.0 至 10.5.1 之前的版本。
漏洞详情
漏洞类型为分类器覆盖不全导致的信任边界绕过。isPrivate 未将 NAT64 本地使用前缀 64:ff9b:1::/48 视为私有,当应用同时使用 isPrivate、isLoopback 和 isLinkLocal 判断地址可信性时,通过该前缀编码的内部 IPv4 地址会被当作外部地址。攻击者需处于使用该本地使用范围内 NAT64 前缀的网络环境,才能利用此误判跨越预期信任边界。
利用条件与风险
利用前提是服务器网络使用运营商选择的、位于本地使用范围内的 NAT64 前缀;满足条件时可绕过网络信任边界,实战风险取决于具体应用的信任决策逻辑。
修复建议
升级至 ip-address 10.5.1 或更高版本;若无法立即升级,可在应用层显式将 64:ff9b:1::/48 视为私有地址进行额外校验。
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1.