GHSA-h3mg-xc3c-68pw: Npm/ip-address vulnerability

Published Sep 29, 2026
·
Updated

Summary

new Address6() and Address6.isValid() place no bound on the length of the string they parse. When the string contains a character that cannot appear in an IPv6 address, the parser builds a diagnostic that wraps every such character in a 34-byte <span class="parse-error">, so the work and the memory scale with the input rather than with an address. A 1 MiB string of ! costs about 110 MB and 70 ms of synchronous work, 8 MiB costs about 800 MB and half a second, 16 MiB throws a RangeError in place of the documented AddressError, and 32 MiB aborts the Node process. isValid() builds the diagnostic and discards it, so a caller that only asks whether a string is valid pays the full price.

An application that validates an attacker-supplied string with these methods can be stalled or crashed by a single oversized request. This is a crash on input that should have been rejected cleanly, which SECURITY.md lists as in scope.

Details

parse() in src/ipv6.ts checks for characters outside [0-9a-f:/%] and, on finding any, throws an AddressError whose parseMessage is the whole input with each offending character wrapped:

ts const badCharacters = address.match(constants6.REBADCHARACTERS);

if (badCharacters) { throw new AddressError( Bad character${badCharacters.length > 1 ? 's' : ''} detected in address: ${badCharacters.join('')}, address.replace(constants6.REBADCHARACTERS, '<span class="parse-error">$1</span>'), ); }

REBADCHARACTERS is /([^0-9a-f:/%])/gi. For an input made entirely of punctuation the match allocates one string per character, the join copies them all into the message, and the replace produces a string 34 times the input. Nothing before this point looks at the length: the constructor strips a CIDR suffix and a zone identifier and hands the rest to parse(). The REBADADDRESS branch below it builds its diagnostic the same way at about a third of the ratio, for input in the hex-and-colon alphabet such as fffff: repeated.

parse() is reached only through the constructor, so every entry point that constructs an Address6 from a string it has not already bounded is affected: new Address6(), isValid(), both arguments of fromAddressAndMask() and fromAddressAndWildcardMask(), fromWildcard(), and the prefix argument of fromAddress4Nat64() and toAddress4Nat64(). fromURL() admits only hex, colons, and dots in a host, so it reaches the REBADADDRESS branch and not the other. fromArpa() caps its input at 32 nibbles before constructing anything, and fromBigInt(), fromByteArray(), and fromAddress4() build the string themselves, so those are unaffected.

The replace is where size becomes fatal. V8 caps a string at 2^29 - 24 characters, so past 16 MiB of input the replace throws RangeError: Invalid string length rather than the AddressError callers catch; isValid() swallows it, but a constructor call guarded by instanceof AddressError does not. Past 32 MiB the replacement builder's internal array exceeds its maximum size and V8 aborts the process with Fatal JavaScript invalid size error, which no try/catch intercepts.

Affected versions

<= 10.7.0. The diagnostic has had this shape since the parser was written, so every release is affected.

Impact

Address6.isValid() on N bytes of !, measured on node 24.19.0:

| Input | Wall time | Transient heap | Outcome | |---|---|---|---| | 16 KiB | 1 ms | 1 MB | false | | 1 MiB | 73 ms | 112 MB | false | | 8 MiB | 464 ms | 784 MB | false | | 16 MiB | | | RangeError: Invalid string length from the constructor; isValid() returns false | | 32 MiB | | | the process aborts |

The parse is synchronous, so the event loop is blocked for the whole of the wall time and nothing else on that process is served. The heap is transient and is reclaimed after the call returns, so memory does not accumulate across requests; the abort at 32 MiB is a single request. Address4 has no diagnostic of this shape and parses the same 8 MiB in a few milliseconds.

Reachability

Reaching the sizes above requires that the application hand the parser a string it has not already bounded. A host taken from a URL or an HTTP header is bounded by the server's header limit (Node's default is 16 KB), and at that size the cost is a millisecond. The megabyte sizes need a request body the application accepts at that scale and passes through unchecked. Common body parsers default to between 100 KB and 1 MB, which caps the effect at a stall of under 100 ms per request, and the abort needs 32 MiB in a single field, which no default admits. The severity is scored for the stall, not the abort: an application that accepts 32 MiB bodies into an address parser is the exception, and the reader running one should treat this as a crash.

Proof of concept

npm i ip-address@10.7.0, then:

js const { Address6 } = require('ip-address');

for (const mib of [1, 8]) { const input = '!'.repeat(mib 1024 1024); const before = process.memoryUsage().heapUsed; const start = process.hrtime.bigint();

Address6.isValid(input);

const ms = Number(process.hrtime.bigint() - start) / 1e6; const mb = (process.memoryUsage().heapUsed - before) / 1048576;

console.log(${mib} MiB: ${ms.toFixed(0)} ms, ${mb.toFixed(0)} MB); }

try { new Address6('!'.repeat(16 1024 1024)); } catch (e) { console.log(16 MiB: ${e.name}: ${e.message}); }

new Address6('!'.repeat(32 1024 1024));

On affected versions (node 24.19.0):

1 MiB: 73 ms, 112 MB 8 MiB: 464 ms, 784 MB 16 MiB: RangeError: Invalid string length

Fatal error in , line 0 Fatal JavaScript invalid size error 142606336

The last line is V8 terminating the process; the script does not reach its end.

Remediation

Upgrade to the patched release. In the fix, the constructor rejects an address longer than the family allows before parse() runs: 45 characters for IPv6 once the CIDR suffix and zone identifier are stripped (six four-digit groups, six colons, and a dotted quad, the same line CPython's ipaddress module draws), and 15 characters for IPv4. The rejection is an AddressError with no parseMessage, so isValid() returns false for the cost of a length comparison and the 32 MiB input above is rejected in the same time as a 46-character one. A zone identifier is not counted, since it never reaches the diagnostic.

This rejects nothing a previous release accepted: every string longer than the limit already failed to parse.

If you cannot upgrade immediately, reject a candidate longer than an address with a zone identifier can be before you parse it:

js if (host.length > 64) throw new Error('not an IP address');

Affected Software

1 affected componentFixes available
npm/ip-address<=10.7.0
10.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/ip-address to a version that resolves this vulnerability.

    Fixed in 10.7.1
  2. Compensating control

    Before parsing attacker-supplied address strings, strip the CIDR suffix and zone identifier, then reject IPv6 candidates longer than 45 characters or IPv4 candidates longer than 15 characters.

Event History

Sep 29, 2026
Advisory Published
via GitHub·11:46 PM
Data Sourced
via GitHub·11:46 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Are applications that only call Address6.isValid() exposed, or only those that construct Address6 objects?

Both methods are affected. Address6.isValid() constructs the same diagnostic and then discards it, so checking validity of an attacker-controlled oversized string still incurs the full memory and synchronous processing cost.

2

What does an attacker need to supply to trigger the resource consumption?

The attacker needs to provide a long string containing characters that cannot appear in an IPv6 address. Each invalid character is wrapped in a 34-byte diagnostic span, causing memory and work to grow with the input size.

3

What failure symptoms can indicate exploitation or attempted exploitation?

A 1 MiB string of invalid characters can consume about 110 MB and 70 ms of synchronous work; 8 MiB can consume about 800 MB and half a second. At 16 MiB the code may throw RangeError instead of AddressError, and at 32 MiB it can abort the Node process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203