Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

github логотип

GHSA-v2v4-37r5-5v8g

3 месяца назад

ip-address has XSS in Address6 HTML-emitting methods

EPSS: Низкий
ubuntu логотип

CVE-2026-42338

3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-42338

3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-42338

3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-42338

3 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

CVSS3: 6.1
EPSS: Низкий
rocky логотип

RLSA-2026:41947

10 дней назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35892

24 дня назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35842

23 дня назад

Important: nodejs22 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-41947

10 дней назад

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35892

23 дня назад

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39868

15 дней назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35891

24 дня назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35841

21 день назад

Important: nodejs24 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39868

11 дней назад

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35891

24 дня назад

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2695-1

около 1 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2647-1

около 1 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21236-1

24 дня назад

Security update for nodejs24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2633-1

около 1 месяца назад

Security update for nodejs24

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21058-1

около 1 месяца назад

Security update for nodejs22

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v2v4-37r5-5v8g

ip-address has XSS in Address6 HTML-emitting methods

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 8.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:41947

Important: nodejs:22 security, bug fix, and enhancement update

10 дней назад
rocky логотип
RLSA-2026:35892

Important: nodejs:22 security, bug fix, and enhancement update

24 дня назад
rocky логотип
RLSA-2026:35842

Important: nodejs22 security, bug fix, and enhancement update

23 дня назад
oracle-oval логотип
ELSA-2026-41947

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

10 дней назад
oracle-oval логотип
ELSA-2026-35892

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

23 дня назад
rocky логотип
RLSA-2026:39868

Important: nodejs:24 security, bug fix, and enhancement update

15 дней назад
rocky логотип
RLSA-2026:35891

Important: nodejs:24 security, bug fix, and enhancement update

24 дня назад
rocky логотип
RLSA-2026:35841

Important: nodejs24 security, bug fix, and enhancement update

21 день назад
oracle-oval логотип
ELSA-2026-39868

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

11 дней назад
oracle-oval логотип
ELSA-2026-35891

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:2695-1

Security update for nodejs22

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2647-1

Security update for nodejs22

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21236-1

Security update for nodejs24

24 дня назад
suse-cvrf логотип
SUSE-SU-2026:2633-1

Security update for nodejs24

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21058-1

Security update for nodejs22

около 1 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.