MODERATEnpm

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

CVE-2026-69198Published 2 days agoUpdated 1 day agoSource: OSV

Affected packages

  • ip-address

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.28%
EPSS percentile
19.9%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 20%.

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks | HackTribune