Fastify · @Fastify/Proxy-Addr · CVE-2026-92395
**Name of the Vulnerable Software and Affected Versions**
@fastify/proxy-addr versions 3.0.0 through 5.1.0
**Description**
This plugin, used to determine a request's client address behind trusted reverse proxies, incorrectly handles trust subnets written in IPv4-mapped IPv6 notation when an IPv4-sized prefix is used (for example, ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104). The software accepts these inputs without error but ends up trusting every IPv4 address on the internet. This allows an unauthenticated client to provide an arbitrary `X-Forwarded-For` header to control the address the application reads, bypassing IP-based access control, rate limiting, geolocation, and audit logging.
**Recommendations**
Update to version 5.1.1 or later.
Ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.