Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

ubuntu логотип

CVE-2026-42338

4 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-42338

4 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-42338

4 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-42338

4 месяца назад

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-v2v4-37r5-5v8g

4 месяца назад

ip-address has XSS in Address6 HTML-emitting methods

EPSS: Низкий
rocky логотип

RLSA-2026:41947

около 2 месяцев назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35892

2 месяца назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35842

2 месяца назад

Important: nodejs22 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-41947

около 2 месяцев назад

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35892

2 месяца назад

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35842

2 месяца назад

ELSA-2026-35842: nodejs22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39868

2 месяца назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35891

2 месяца назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35841

2 месяца назад

Important: nodejs24 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39868

около 2 месяцев назад

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35891

2 месяца назад

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35841

2 месяца назад

ELSA-2026-35841: nodejs24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2695-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2647-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21236-1

2 месяца назад

Security update for nodejs24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 8.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

CVSS3: 6.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-42338

ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-v2v4-37r5-5v8g

ip-address has XSS in Address6 HTML-emitting methods

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:41947

Important: nodejs:22 security, bug fix, and enhancement update

около 2 месяцев назад
rocky логотип
RLSA-2026:35892

Important: nodejs:22 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35842

Important: nodejs22 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-41947

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-35892

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-35842

ELSA-2026-35842: nodejs22 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
rocky логотип
RLSA-2026:39868

Important: nodejs:24 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35891

Important: nodejs:24 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35841

Important: nodejs24 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-39868

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-35891

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-35841

ELSA-2026-35841: nodejs24 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2695-1

Security update for nodejs22

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2647-1

Security update for nodejs22

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21236-1

Security update for nodejs24

2 месяца назад

Уязвимостей на страницу