THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4xrf-jv44-h6hh (medium) — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

[GHSA] GHSA-4xrf-jv44-h6hh (medium) — ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

highgithub_advisoriesPublished 2026-08-03

GHSA-4xrf-jv44-h6hh Severity: medium CVE: CVE-2026-69198

ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks

### Summary

Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address's own subnet mask is *shorter* than the reference range's mask. That mask com

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4xrf-jv44-h6hh