Listen to this Post
CVE-2026-101911 is an uncontrolled resource consumption vulnerability in the `ip-address` library for Node.js, affecting all versions prior to 10.7.1. The flaw resides in the `Address6` constructor, Address6.isValid(), and the underlying `parse()` function within src/ipv6.ts. These entry points accept an unbounded string and attempt to parse it as an IPv6 address without first enforcing a maximum length. When the input contains a character that is invalid for an IPv6 address, the parser builds a diagnostic error message. This message is constructed by wrapping each offending character in a 34-byte HTML span element (<span class="parse-error">). Consequently, the memory consumed and processing time required scale linearly with the total length of the input string rather than with the length of a valid address. For instance, a 1 MiB string consisting entirely of the `!` character consumes approximately 110 MB of transient heap memory and blocks the event loop for about 70 ms of synchronous work. An 8 MiB input costs roughly 800 MB and half a second. When the input reaches 16 MiB, the string replacement operation exceeds V8’s maximum string length, throwing a `RangeError` instead of the expected AddressError. At 32 MiB, the internal array of the replacement builder exceeds its maximum size, causing V8 to abort the entire Node.js process with a fatal error that cannot be caught by try/catch. Critically, the `isValid()` method constructs this full diagnostic and then discards it, meaning a simple validation check incurs the complete resource cost. An application that passes an attacker-controlled string to these methods without a prior length check can be stalled or crashed by a single oversized request, resulting in a denial of service. The vulnerability is classified as medium severity with a CVSS score of 6.3. The primary remediation is to upgrade the `ip-address` library to version 10.7.1 or later, which introduces a length check before parsing.
DailyCVE Form:
Platform: Node.js
Version: <= 10.7.0
Vulnerability: CVE-2026-101911
Severity: Medium (6.3)
date: 2026-09-28
Prediction: Patched 2026-09-29
What Undercode Say
The following commands demonstrate the vulnerability in a controlled environment using Node.js.
npm install [email protected]
const { Address6 } = require('ip-address');
// Test the synchronous stall and memory usage
for (const mib of [1, 8]) {
const input = '!'.repeat(mib 1024 1024);
const before = process.memoryUsage().heapUsed;
const start = process.hrtime.bigint();
Address6.isValid(input);
const ms = Number(process.hrtime.bigint() - start) / 1e6;
const mb = (process.memoryUsage().heapUsed - before) / 1048576;
console.log(<code>${mib} MiB: ${ms.toFixed(0)} ms, ${mb.toFixed(0)} MB</code>);
}
// Trigger the RangeError
try {
new Address6('!'.repeat(16 1024 1024));
} catch (e) {
console.log(<code>16 MiB: ${e.name}: ${e.message}</code>);
}
// Trigger the process abort (Fatal JavaScript invalid size error)
new Address6('!'.repeat(32 1024 1024));
Exploit: (Educational Purposes!)
This section describes how an attacker could exploit the vulnerability. The attack is a classic resource exhaustion denial of service. An attacker identifies an application endpoint that accepts a user-supplied string and passes it to the `Address6` constructor or the `Address6.isValid()` method without first validating the input length. The attacker then crafts a request containing an extremely long string (e.g., 8 MiB, 16 MiB, or 32 MiB) of characters that are invalid for an IPv6 address, such as repeated exclamation marks (!) or other punctuation. When the application processes this request, the Node.js event loop is blocked synchronously for the entire duration of the parsing and diagnostic generation. At smaller payloads (e.g., 1–8 MiB), this results in a noticeable stall, preventing the server from handling other requests. At larger payloads (e.g., 16 MiB), a `RangeError` may be thrown if not properly caught, potentially causing an unhandled exception that could crash the request handler. At 32 MiB, the Node.js process itself is aborted by the V8 engine due to the fatal memory allocation error, taking down the entire service. This exploitation requires no authentication and can be triggered remotely, provided the application’s request body size limits are configured to allow payloads of this magnitude.
Protection: from this CVE
The primary and most effective protection is to upgrade the `ip-address` library to version 10.7.1 or later. In the patched version, the `Address6` constructor rejects an address longer than the family allows before the `parse()` function executes. The limit is 45 characters for IPv6 (after stripping a CIDR suffix and zone identifier) and 15 characters for IPv4. This rejection is an `AddressError` with no parseMessage, so `isValid()` returns `false` for the cost of a simple length comparison. If an immediate upgrade is not possible, developers should implement an input length validation check before passing any string to the `Address6` constructor or `isValid()` method. A simple check such as `if (host.length > 64) throw new Error(‘not an IP address’);` will prevent the oversized input from reaching the vulnerable parser. Additionally, configuring application-level request body parsers with strict size limits (e.g., 100 KB) will prevent the megabyte-scale payloads required to trigger the stall, though the 32 MiB abort requires a single field of that size, which most default configurations would already reject.
Impact
The impact of this vulnerability is a denial of service (DoS). A successful exploitation can cause a synchronous stall of the Node.js event loop, making the application unresponsive to all other users for the duration of the processing time (tens of milliseconds to half a second per request). At 16 MiB, the parser throws a `RangeError` that, if unhandled, can terminate the request handler or cause unexpected application behavior. At 32 MiB, the Node.js process is aborted entirely, resulting in a complete service outage. The heap memory used is transient and reclaimed after the call returns, so memory does not accumulate across multiple requests; however, the single-request abort at 32 MiB is sufficient to crash the process. The vulnerability is not known to allow arbitrary code execution or data exfiltration; its sole impact is resource consumption and process termination.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

