PT-2026-91873 · Npm · Proxy-Addr

·

CVE-2026-90711

·

Published

2026-09-15

·

Updated

2026-10-05

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions proxy-addr versions 1.1.0 through 2.0.7
Description This Node.js module, which determines a request's client address behind trusted reverse proxies and supports Express req.ip and req.ips, contains a flaw where trust subnets written in IPv4-mapped IPv6 notation with an IPv4-sized prefix (e.g., ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104) are accepted without error. This causes the module to trust every IPv4 address on the internet instead of the specified block. Consequently, an unauthenticated client can provide an arbitrary X-Forwarded-For header to control the address the application reads, bypassing IP-based access control, rate limiting, geolocation, and audit logging.
Recommendations Update to version 2.0.8 or later. Ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97. Express the trust range in plain IPv4 notation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101775
CVE-2026-90711
GHSA-JQCG-44MW-7W3H

Affected Products

Proxy-Addr