Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42338

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 8.1

Описание

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.

Отчет

This vulnerability in the ip-address JavaScript library is rated as Important. It allows for cross-site scripting (XSS) when an application processes untrusted input through the Address6 constructor and subsequently renders the unescaped output of methods like Address6.group(), Address6.link(), or AddressError.parseMessage directly as HTML. While the library itself is affected, exploitation is contingent on specific application-level rendering practices that may not be common in Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-pccsAffected
Cryostat 4cryostat/cryostat-openshift-console-plugin-rhel9Not affected
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Will not fix
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Not affected
Red Hat AMQ Broker 7ip-addressAffected
Red Hat build of Apache Camel for Spring Boot 4ip-addressNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2476810ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
nvd
3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
debian
3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

github
3 месяца назад

ip-address has XSS in Address6 HTML-emitting methods

rocky
10 дней назад

Important: nodejs:22 security, bug fix, and enhancement update

8.1 High

CVSS3