Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2023-50570: IPAddress v5.1.0 Can Get Stuck in a Loop with Bad Input

CVE-2023-50570 · published 2 years ago
Summary

The IPAddress component in version 5.1.0 of the software can enter an infinite loop if it's given incorrect data. This is only a concern if you're passing it bad information. To stay safe, make sure you're only feeding it valid data.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
Ecosystem VendorProductAffected versions
maven github com.github.seancfoley:ipaddress <= 5.4.0
– seancfoley ipaddress 5.1.0
cpe:2.3:a:seancfoley:ipaddress:5.1.0:*:*:*:*:*:*:*
Original advisory text
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invali...
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invalid arguments. The product is not intended to always halt for contrived inputs.
Severity
5.5 Medium
CVSS 3.1: 5.5 (GHSA)
Exploitation
EPSS <1%
Type
CWE-835
Timeline
Published29 Dec 2023
Updated15 Aug 2026
First seen6 Mar 2026
Sources
Monitor software like this
Free during beta