boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-42338

beaugunderson ip-address — ip-address: XSS in Address6 HTML-emitting methods
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   L   L   N    5.3   .0051   41.5     —
AFFECTED
  Product     Versions    Fixed
  ip-address  < 10.1.1 –  —
TIMELINE
  Apr 26  Reserved by GitHub_M
  May 12  Published (CNA: GitHub_M)
  Aug 24  EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Aug 26  EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Aug 28  EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Sep 2   EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Sep 3   EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Sep 7   EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Sep 9   EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
  Sep 11  EXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
CWE-79 · CNA: GitHub_M · CVSS v4.0 · 34 references · NVD status: Modified

Description

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.

Lifecycle

Complete event history — 10 events, chronological
DateEventDetail
April 26, 2026ReservedReserved by GitHub_M
May 12, 2026PublishedPublished (CNA: GitHub_M)
August 24, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
August 26, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
August 28, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
September 2, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
September 3, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
September 7, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
September 9, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.
September 11, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-42338 (beaugunderson ip-address). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
beaugundersonip-address—< 10.1.1—

Weaknesses

CWE-79

References (34)

Related

Authoritative record: CVE-2026-42338 at cve.org

Vendors: beaugunderson

Weaknesses: CWE-79

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-42338 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.