PT-2026-5492 · Unknown · Crystal Shard Http-Protection

·

CVE-2020-37056

·

Published

2026-01-30

·

Updated

2026-01-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crystal Shard http-protection version 0.2.0
Description The software contains an IP spoofing issue that allows attackers to bypass protection middleware. This is achieved by manipulating request headers to hardcode consistent IP values across the X-Forwarded-For, X-Client-IP, and X-Real-IP headers, circumventing security checks and potentially gaining unauthorized access.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37056

Affected Products

Crystal Shard Http-Protection