AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

PIIMiddleware "Ip" Type Fails To Detect IPv6 Addresses, Allowing PII Leakage

The PIIMiddleware with type="ip" only compiles an IPv4 regex, so IPv6 addresses are not redacted or blocked, causing silent PII leakage to the model.

highConfidence 95%LangchainAffected V1.3.16

Origin Analysis

In langchain/agents/middleware/_redaction.py, detect_ip() uses only an IPv4 pattern (`\b(?:[0-9]{1,3}\.){3}[0-9]{1,3}\b`) despite its docstring claiming IPv4 or IPv6 support. The validation helper `ipaddress.ip_address()` already accepts both families, but no IPv6 candidate pattern is ever considered, so IPv6 strings never reach validation.
Run the provided Python code: instantiate PIIMiddleware("ip", strategy="redact") with a message containing an IPv6 address (e.g., "Server IP: 2001:0db8:85a3:0000:0000:8a2e:0370:7334"); observe the address is not redacted. Similarly with strategy="block", no PIIDetectionError is raised.

Fixing Code Block

Edge Case Audit

Behavior change: IPv4-mapped IPv6 addresses (e.g., ::ffff:192.168.1.1) will now be fully matched and redacted/hashed as a unit, altering previous redaction output and hash digests. This may affect audit logs or hash-based deduplication. Rollback: if necessary, revert to the previous IPv4-only pattern, but this reintroduces the leakage. Test thoroughly with various IPv6 formats, IPv4-mapped addresses, and non-IP colon strings to avoid false positives. The function is stateless, so no concurrency issues, but ensure any cached compiled regexes are versioned appropriately across deployments.

Ecosystem Topology