PT-2026-91873 · Npm · Proxy-Addr
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
proxy-addr versions 1.1.0 through 2.0.7
Description
This Node.js module, which determines a request's client address behind trusted reverse proxies and supports Express
req.ip and req.ips, contains a flaw where trust subnets written in IPv4-mapped IPv6 notation with an IPv4-sized prefix (e.g., ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104) are accepted without error. This causes the module to trust every IPv4 address on the internet instead of the specified block. Consequently, an unauthenticated client can provide an arbitrary X-Forwarded-For header to control the address the application reads, bypassing IP-based access control, rate limiting, geolocation, and audit logging.Recommendations
Update to version 2.0.8 or later.
Ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97.
Express the trust range in plain IPv4 notation.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proxy-Addr