THREAT OPS › Threat News › [GHSA] GHSA-22jq-vg5j-6vgg (medium) — ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
[GHSA] GHSA-22jq-vg5j-6vgg (medium) — ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
GHSA-22jq-vg5j-6vgg Severity: medium CVE: CVE-2026-54272
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
### Summary
`Address6`'s special-property checks misclassify IPv4-mapped (`::ffff:0:0/96`) and NAT64 well-known (`64:ff9b::/96`) IPv6 addresses. These checks classify an address by its IPv6 wrapper rather than by the IPv4 address it
Indicators of compromise
- CVE-2026-54272cve
- 100.64.0.1ipv4
- 8.8.8.8ipv4
- 127.0.0.0/8cidr
Original source: https://github.com/advisories/GHSA-22jq-vg5j-6vgg