ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4(012.0.0.1) reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch(http://012.0.0.1/) connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Cryostat 4 on RHEL 9 | RedHat | cryostat/cryostat-openshift-console-plugin-rhel9:4.2.0-14 | * |
| Red Hat Enterprise Linux 10 | RedHat | nodejs22-1:22.23.1-6.el10_2 | * |
| Red Hat Enterprise Linux 10 | RedHat | rh-podman-desktop-0:1.1.2-1.el10_2 | * |
| Red Hat Enterprise Linux 10 | RedHat | nodejs24-1:24.18.0-5.el10_2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | nodejs22-1:22.23.2-1.el10_0 | * |
| Red Hat Enterprise Linux 8 | RedHat | nodejs:24-8100020260807112957.6d880403 | * |
| Red Hat Enterprise Linux 8 | RedHat | nodejs:22-8100020260807115047.6d880403 | * |
| Red Hat Enterprise Linux 9 | RedHat | nodejs:22-9080020260806135640.rhel9 | * |
| Red Hat Enterprise Linux 9 | RedHat | nodejs:24-9080020260806135511.rhel9 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | nodejs:22-9060020260901085634.rhel9 | * |
| Multicluster engine for Kubernetes 2.17 | RedHat | multicluster-engine/console-mce-rhel9:1786668856 | * |
| Multicluster engine for Kubernetes 2.6 | RedHat | multicluster-engine/console-mce-rhel9:1787264250 | * |
| Multicluster engine for Kubernetes 2.8 | RedHat | multicluster-engine/console-mce-rhel9:1787259048 | * |
| Multicluster engine for Kubernetes 2.9 | RedHat | multicluster-engine/console-mce-rhel9:1787079359 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.11 | RedHat | rhacm2/console-rhel9:1787687062 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | RedHat | rhacm2/console-rhel9:1787339249 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.14 | RedHat | rhacm2/console-rhel9:1787339248 | * |
| Red Hat Advanced Cluster Management for Kubernetes 2.17 | RedHat | rhacm2/console-rhel9:1787335105 | * |
| Red Hat Ansible Automation Platform 2.1 | RedHat | ansible-automation-platform/automation-portal:1787047114 | * |
| Red Hat Ansible Automation Platform 2.2 | RedHat | ansible-automation-platform/automation-portal:1787047188 | * |
| Red Hat Ansible Automation Platform 2.2 | RedHat | ansible-automation-platform/bootc-automation-portal-rhel9:1788943531 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed:1788187400 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1788186854 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator:1788186989 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1788187326 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1788187449 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets:1788186625 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1788187032 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed:1788187400 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1788186854 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator:1788186989 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1788187326 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1788187449 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets:1788186625 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1788187032 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/rhdh-hub-rhel9:1788286049 | * |
| Red Hat Developer Hub 1.9 | RedHat | rhdh/rhdh-hub-rhel9:1789554285 | * |
| Red Hat Hardened Images | RedHat | grafana13-1-main-13.1.1-0.5.2.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.6-0.4.1.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana13-1-main-13.1.2-0.1.hum1 | * |
| Red Hat Hardened Images | RedHat | grafana12-4-main-12.4.7-0.1.hum1 | * |
| Red Hat Migration Toolkit 1.8 | RedHat | rhmtc/openshift-migration-ui-rhel8:1789546373 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787801527 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1790013905 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787121387 | * |
| Red Hat OpenShift Container Platform 4.20 | RedHat | openshift4/ose-agent-installer-ui-rhel9:1788335236 | * |
| Red Hat OpenShift Container Platform 4.22 | RedHat | openshift4/ose-agent-installer-ui-rhel9:1788314963 | * |
| Red Hat OpenShift Dev Spaces 3.30 | RedHat | devspaces/code-rhel9:1789145741 | * |
| Red Hat OpenShift Dev Spaces 3.30 | RedHat | devspaces/dashboard-rhel9:1789162884 | * |
| Red Hat OpenShift Dev Spaces 3.30 | RedHat | devspaces/openvsx-rhel9:1789144269 | * |
| Red Hat OpenShift Service Mesh 3.0 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:1787077028 | * |
| Red Hat OpenShift Service Mesh 3.0 | RedHat | openshift-service-mesh/kiali-rhel9:1787076495 | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:1787075730 | * |
| Red Hat OpenShift Service Mesh 3.1 | RedHat | openshift-service-mesh/kiali-rhel9:1787092198 | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:1787077188 | * |
| Red Hat OpenShift Service Mesh 3.2 | RedHat | openshift-service-mesh/kiali-rhel9:1787092255 | * |
| Red Hat OpenShift Service Mesh 3.3 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:1787076322 | * |
| Red Hat OpenShift Service Mesh 3.3 | RedHat | openshift-service-mesh/kiali-rhel9:1787077108 | * |
| Red Hat OpenShift Service Mesh 3.4 | RedHat | openshift-service-mesh/kiali-ossmc-rhel9:1787166293 | * |
| Red Hat OpenShift Service Mesh 3.4 | RedHat | openshift-service-mesh/kiali-rhel9:1787165683 | * |
| Red Hat Satellite 6.18 | RedHat | satellite/iop-remediations-rhel9:1788230538 | * |
| Red Hat Satellite 6.19 | RedHat | satellite/iop-remediations-rhel9:1788253940 | * |
| Node-ip-address | Ubuntu | upstream | * |
Input validation is a frequently-used technique for checking potentially dangerous inputs in order to ensure that the inputs are safe for processing within the code, or when communicating with other components. Input can consist of:
Data can be simple or structured. Structured data can be composed of many nested layers, composed of combinations of metadata and raw data, with other simple or structured data. Many properties of raw data or metadata may need to be validated upon entry into the code, such as:
Implied or derived properties of data must often be calculated or inferred by the code itself. Errors in deriving properties may be considered a contributing factor to improper input validation.