What is CVE-2026-54272?
CVE-2026-54272 is an SSRF vulnerability in the JavaScript ip-address library due to misclassification of IPv4-mapped/NAT64 IPv6 addresses, affecting versions 10.1.1 through 10.2.0. This flaw allows attackers to trick the server into making requests to internal networks. Upgrading to version 10.2.1 or later is strongly recommended.
Azərbaycanca: CVE-2026-54272, JavaScript ip-address kitabxanasında IPv4-mapped/NAT64 IPv6 ünvanlarının yanlış təsnifatı nəticəsində SSRF (Server-Side Request Forgery) boşluğudur. 10.1.1-dən 10.2.0-ə qədər versiyalar təsirlənir, bu zəiflik təcavüzkara serveri aldadaraq daxili şəbəkəyə sorğu göndərməyə imkan verir. Təsirlənən versiyalardan ən yenisi olan 10.2.1 və ya daha yuxarısına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What vulnerability does CVE-2026-54272 cause in the JavaScript ip-address library?
CVE-2026-54272 causes an SSRF vulnerability in the JavaScript ip-address library due to the misclassification of IPv4-mapped/NAT64 IPv6 addresses.
Which version is recommended to upgrade to in order to fix CVE-2026-54272?
Upgrading the ip-address library to version 10.2.1 or later is recommended to fix CVE-2026-54272.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.