CVE-2026-101913 ip-address 信任边界绕过漏洞
影响攻击者可绕过基于链路本地地址的信任边界检查
ip-address 是 JavaScript 中用于解析和操作 IPv4/IPv6 地址的库。其 Address6 的 isLinkLocal 方法在 10.5.1 之前仅识别 fe80::/64,而非完整的 fe80::/10 链路本地范围,导致分类不一致。攻击者控制的 fe80::/10 内其他地址可绕过依赖 isLinkLocal 的信任边界检查。
影响范围
ip-address 库 10.5.1 之前的版本。
漏洞详情
漏洞类型为信任边界绕过/分类不一致。isLinkLocal 只匹配 fe80::/64,而 getType 和 getScope 将整个 fe80::/10 视为链路本地,造成同一地址判定矛盾。攻击者可构造 fe80::/10 中非 fe80::/64 的地址,使依赖 isLinkLocal 的检查误判为可信,从而访问预期信任边界外的同链路主机。
利用条件与风险
利用前提是应用使用 isLinkLocal 作为信任边界判断且地址可由攻击者控制;实战中可导致绕过访问控制,风险中等。
修复建议
升级至 ip-address 10.5.1 或更高版本;临时缓解可改用 getType/getScope 或自行校验完整 fe80::/10 范围。
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1.