Bug 2510803 (CVE-2026-69198)

Summary: CVE-2026-69198 ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, alizardo, anthomas, ataylor, bbrownin, cdrage, cmah, dbruscin, dfreiber, drow, dschmidt, dymurray, eaguilar, ebaron, ehelms, ehugonne, fmariani, ggainey, ggrzybek, gmalinko, gparvin, gtanzill, ibolton, janstey, jburrell, jbuscemi, jchui, jhe, jlanda, jmatsuok, jmatthew, jmontleo, jpasqual, jraez, jtolenti, juwatts, jwong, jwon, kshier, ktsao, kvanderr, mcarlett, mdellweg, mhulan, mstipich, nboldt, nmoumoul, oaljalju, omaciel, osousa, parichar, pcreech, pgaikwad, pjindal, psrna, rchan, rexwhite, rhaigner, rhel-process-autobot, rjohnson, rstepani, rushinde, sdawley, simaishi, slucidi, smallamp, sseago, stcannon, sthirugn, tasato, tcunning, teagle, tmalecek, vkumar, watson-tool-maintainers, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in ip-address, a JavaScript library for parsing and manipulating IP addresses. By appending a Classless Inter-Domain Routing (CIDR) suffix to an IP address, an attacker can bypass the library's special-use classification methods. This misclassification can lead applications, such as those designed to prevent Server-Side Request Forgery (SSRF), to incorrectly treat internal network targets as external. Consequently, an attacker may be able to access internal resources or bypass other network trust-boundary checks.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2510938, 2510939, 2510940, 2510941, 2510942, 2510943, 2510944    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-03 21:02:53 UTC
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.