HIGHnpm

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

CVE-2026-69192Published 2 days agoUpdated 1 day agoSource: OSV

Affected packages

  • ip-address

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.29%
EPSS percentile
21.5%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 21%.

ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass | HackTribune