CVE-2023-50570
Description
An issue in the component IPAddressBitsDivision of IPAddress v5.1.0 leads to an infinite loop. This is disputed because an infinite loop occurs only for cases in which the developer supplies invalid arguments. The product is not intended to always halt for contrived inputs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A bug in IPAddress v5.1.0's IPAddressBitsDivision can cause an infinite loop when provided with invalid arguments, though the developer disputes this as by-design behavior for contrived inputs.
Vulnerability
Description The IPAddress library version 5.1.0 contains an issue in the IPAddressBitsDivision component that can cause an infinite loop when supplied with invalid arguments [1]. Specifically, passing certain long and integer values to the constructor leads to a non-terminating computation [3].
Exploitation
Conditions An attacker could exploit this by providing crafted input to methods that utilize IPAddressBitsDivision, such as equals() [3]. No authentication is required if the library processes external data. The developer notes that the library is not intended to handle contrived inputs, and the infinite loop occurs only for invalid arguments [4].
Impact
Successful exploitation results in a denial-of-service condition due to the infinite loop, potentially affecting application availability [1].
Mitigation
Users should upgrade to a newer version of the IPAddress library (e.g., 5.6.2) where the issue may be resolved [2]. Alternatively, ensure that only valid arguments are passed to the library.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.github.seancfoley:ipaddressMaven | <= 5.4.0 | — |
Affected products
137- IPAddress/IPAddressdescription
- osv-coords136 versionspkg:apk/chainguard/trinopkg:apk/chainguard/trino-configpkg:apk/chainguard/trino-oci-entrypointpkg:apk/chainguard/trino-plugin-accumulopkg:apk/chainguard/trino-plugin-ai-functionspkg:apk/chainguard/trino-plugin-atoppkg:apk/chainguard/trino-plugin-bigquerypkg:apk/chainguard/trino-plugin-blackholepkg:apk/chainguard/trino-plugin-cassandrapkg:apk/chainguard/trino-plugin-clickhousepkg:apk/chainguard/trino-plugin-delta-lakepkg:apk/chainguard/trino-plugin-druidpkg:apk/chainguard/trino-plugin-duckdbpkg:apk/chainguard/trino-plugin-elasticsearchpkg:apk/chainguard/trino-plugin-example-httppkg:apk/chainguard/trino-plugin-exasolpkg:apk/chainguard/trino-plugin-exchange-filesystempkg:apk/chainguard/trino-plugin-exchange-hdfspkg:apk/chainguard/trino-plugin-fakerpkg:apk/chainguard/trino-plugin-functions-pythonpkg:apk/chainguard/trino-plugin-geospatialpkg:apk/chainguard/trino-plugin-google-sheetspkg:apk/chainguard/trino-plugin-hivepkg:apk/chainguard/trino-plugin-http-event-listenerpkg:apk/chainguard/trino-plugin-http-server-event-listenerpkg:apk/chainguard/trino-plugin-hudipkg:apk/chainguard/trino-plugin-icebergpkg:apk/chainguard/trino-plugin-ignitepkg:apk/chainguard/trino-plugin-jmxpkg:apk/chainguard/trino-plugin-kafkapkg:apk/chainguard/trino-plugin-kafka-event-listenerpkg:apk/chainguard/trino-plugin-kinesispkg:apk/chainguard/trino-plugin-kudupkg:apk/chainguard/trino-plugin-lakehousepkg:apk/chainguard/trino-plugin-ldap-group-providerpkg:apk/chainguard/trino-plugin-local-filepkg:apk/chainguard/trino-plugin-lokipkg:apk/chainguard/trino-plugin-mariadbpkg:apk/chainguard/trino-plugin-memorypkg:apk/chainguard/trino-plugin-mlpkg:apk/chainguard/trino-plugin-mongodbpkg:apk/chainguard/trino-plugin-mysqlpkg:apk/chainguard/trino-plugin-mysql-event-listenerpkg:apk/chainguard/trino-plugin-opapkg:apk/chainguard/trino-plugin-openlineagepkg:apk/chainguard/trino-plugin-opensearchpkg:apk/chainguard/trino-plugin-oraclepkg:apk/chainguard/trino-plugin-password-authenticatorspkg:apk/chainguard/trino-plugin-phoenix5pkg:apk/chainguard/trino-plugin-pinotpkg:apk/chainguard/trino-plugin-postgresqlpkg:apk/chainguard/trino-plugin-prometheuspkg:apk/chainguard/trino-plugin-rangerpkg:apk/chainguard/trino-plugin-raptor-legacypkg:apk/chainguard/trino-plugin-redispkg:apk/chainguard/trino-plugin-redshiftpkg:apk/chainguard/trino-plugin-resource-group-managerspkg:apk/chainguard/trino-plugin-session-property-managerspkg:apk/chainguard/trino-plugin-singlestorepkg:apk/chainguard/trino-plugin-snowflakepkg:apk/chainguard/trino-plugin-spooling-filesystempkg:apk/chainguard/trino-plugin-sqlserverpkg:apk/chainguard/trino-plugin-teradata-functionspkg:apk/chainguard/trino-plugin-thriftpkg:apk/chainguard/trino-plugin-tpcdspkg:apk/chainguard/trino-plugin-tpchpkg:apk/chainguard/trino-plugin-verticapkg:apk/wolfi/trinopkg:apk/wolfi/trino-configpkg:apk/wolfi/trino-oci-entrypointpkg:apk/wolfi/trino-plugin-accumulopkg:apk/wolfi/trino-plugin-ai-functionspkg:apk/wolfi/trino-plugin-atoppkg:apk/wolfi/trino-plugin-bigquerypkg:apk/wolfi/trino-plugin-blackholepkg:apk/wolfi/trino-plugin-cassandrapkg:apk/wolfi/trino-plugin-clickhousepkg:apk/wolfi/trino-plugin-delta-lakepkg:apk/wolfi/trino-plugin-druidpkg:apk/wolfi/trino-plugin-duckdbpkg:apk/wolfi/trino-plugin-elasticsearchpkg:apk/wolfi/trino-plugin-example-httppkg:apk/wolfi/trino-plugin-exasolpkg:apk/wolfi/trino-plugin-exchange-filesystempkg:apk/wolfi/trino-plugin-exchange-hdfspkg:apk/wolfi/trino-plugin-fakerpkg:apk/wolfi/trino-plugin-functions-pythonpkg:apk/wolfi/trino-plugin-geospatialpkg:apk/wolfi/trino-plugin-google-sheetspkg:apk/wolfi/trino-plugin-hivepkg:apk/wolfi/trino-plugin-http-event-listenerpkg:apk/wolfi/trino-plugin-http-server-event-listenerpkg:apk/wolfi/trino-plugin-hudipkg:apk/wolfi/trino-plugin-icebergpkg:apk/wolfi/trino-plugin-ignitepkg:apk/wolfi/trino-plugin-jmxpkg:apk/wolfi/trino-plugin-kafkapkg:apk/wolfi/trino-plugin-kafka-event-listenerpkg:apk/wolfi/trino-plugin-kinesispkg:apk/wolfi/trino-plugin-kudupkg:apk/wolfi/trino-plugin-lakehousepkg:apk/wolfi/trino-plugin-ldap-group-providerpkg:apk/wolfi/trino-plugin-local-filepkg:apk/wolfi/trino-plugin-lokipkg:apk/wolfi/trino-plugin-mariadbpkg:apk/wolfi/trino-plugin-memorypkg:apk/wolfi/trino-plugin-mlpkg:apk/wolfi/trino-plugin-mongodbpkg:apk/wolfi/trino-plugin-mysqlpkg:apk/wolfi/trino-plugin-mysql-event-listenerpkg:apk/wolfi/trino-plugin-opapkg:apk/wolfi/trino-plugin-openlineagepkg:apk/wolfi/trino-plugin-opensearchpkg:apk/wolfi/trino-plugin-oraclepkg:apk/wolfi/trino-plugin-password-authenticatorspkg:apk/wolfi/trino-plugin-phoenix5pkg:apk/wolfi/trino-plugin-pinotpkg:apk/wolfi/trino-plugin-postgresqlpkg:apk/wolfi/trino-plugin-prometheuspkg:apk/wolfi/trino-plugin-rangerpkg:apk/wolfi/trino-plugin-raptor-legacypkg:apk/wolfi/trino-plugin-redispkg:apk/wolfi/trino-plugin-redshiftpkg:apk/wolfi/trino-plugin-resource-group-managerspkg:apk/wolfi/trino-plugin-session-property-managerspkg:apk/wolfi/trino-plugin-singlestorepkg:apk/wolfi/trino-plugin-snowflakepkg:apk/wolfi/trino-plugin-spooling-filesystempkg:apk/wolfi/trino-plugin-sqlserverpkg:apk/wolfi/trino-plugin-teradata-functionspkg:apk/wolfi/trino-plugin-thriftpkg:apk/wolfi/trino-plugin-tpcdspkg:apk/wolfi/trino-plugin-tpchpkg:apk/wolfi/trino-plugin-verticapkg:maven/com.github.seancfoley/ipaddresspkg:rpm/opensuse/IPAddress&distro=openSUSE%20Tumbleweed
< 472-r0+ 135 more
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: < 472-r0
- (no CPE)range: <= 5.4.0
- (no CPE)range: < 5.5.1-1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.