MEDIUM
beaugunderson
CVE published 2026-07-27
CVE-2026-54272
CVE-2026-54272 is a Server-Side Request Forgery (SSRF) vulnerability in the ip-address library for JavaScript, affecting versions 10.1.1 through 10.2.0. The vulnerability arises from the misclassification of IPv4-mapped/NAT64 IPv6 addresses. The Address6.getType() method classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. [truncated]