PT-2026-53661 · Unknown · Libretranslate

·

CVE-2026-57942

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreTranslate versions prior to 1.9.8
Description An issue exists in the get remote address() function that allows unauthenticated attackers to spoof client IP addresses. This is achieved by injecting arbitrary values into the X-Forwarded-For header, which the system processes without proper trusted proxy validation. By supplying forged addresses, attackers can bypass per-IP rate limiting and flood bans, enabling unlimited API abuse.
Recommendations Update LibreTranslate to version 1.9.8 or apply the fix from commit 397fd22.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57942

Affected Products

Libretranslate