PT-2026-53661 · Unknown · Libretranslate
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreTranslate versions prior to 1.9.8
Description
An issue exists in the
get remote address() function that allows unauthenticated attackers to spoof client IP addresses. This is achieved by injecting arbitrary values into the X-Forwarded-For header, which the system processes without proper trusted proxy validation. By supplying forged addresses, attackers can bypass per-IP rate limiting and flood bans, enabling unlimited API abuse.Recommendations
Update LibreTranslate to version 1.9.8 or apply the fix from commit 397fd22.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libretranslate