PatchSiren

beaugunderson CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM beaugunderson CVE published 2026-07-27

CVE-2026-54272

CVE-2026-54272 is a Server-Side Request Forgery (SSRF) vulnerability in the ip-address library for JavaScript, affecting versions 10.1.1 through 10.2.0. The vulnerability arises from the misclassification of IPv4-mapped/NAT64 IPv6 addresses. The Address6.getType() method classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. [truncated]