---
title: "CVE-2026-101911\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-101911?format=md
keywords: index, follow
---

# CVE-2026-101911

Publication date 29 September 2026

Last updated 29 September 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

ip-address is a library for parsing and manipulating IPv4 and IPv6
addresses in JavaScript. Prior to 10.7.1, the Address6 constructor,
Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings
and expand invalid characters through RE\_BAD\_CHARACTERS into large
diagnostics. Material impact occurs only when an application accepts a very
large attacker-controlled field and passes it to Address6 parsing without
an earlier length bound. Common URL and header limits, and common
body-parser defaults, generally constrain the effect; common defaults
typically exclude 32 MiB fields. Megabyte-scale fields can cause a
synchronous stall and high transient memory use, approximately 16 MiB can
trigger an invalid string length exception, and process termination occurs
at approximately 32 MiB. The affected entry points include Address6.isValid
and construction paths that reach parse. This issue is fixed in version
10.7.1.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| node-ip-address | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v4.0

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-101911)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-101911)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-101911)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-101911)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-101911>
* <https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw>
* <https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134>
* <https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5>
* <https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1>
