MODERATEnpm

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks

CVE-2026-54272Published 2 days agoUpdated 1 day agoSource: OSV

Affected packages

  • ip-address

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.25%
EPSS percentile
16.9%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 17%.

ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks | HackTribune