PT-2026-55275 · Fiber · Fiber
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fiber versions prior to 3.3.0
Fiber versions prior to 2.52.14
Description
The
BalancerForward proxy helper in middleware/proxy/proxy.go uses the Header.Add() function instead of Header.Set() when injecting the X-Real-IP header. This behavior appends the real client IP as a second value rather than replacing any existing value provided by a user. Consequently, upstream servers that read only the first X-Real-IP header may use an attacker-supplied spoofed IP for logging, rate limiting, and access control, potentially leading to IP ACL bypass, rate limit bypass, audit log poisoning, and geolocation bypass.Recommendations
Update Fiber to version 3.3.0 or later.
Update Fiber to version 2.52.14 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fiber