PT-2026-93809 · Fastify · @Fastify/Proxy-Addr
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@fastify/proxy-addr versions 3.0.0 through 5.1.0
Description
This plugin, used to determine a request's client address behind trusted reverse proxies, incorrectly handles trust subnets written in IPv4-mapped IPv6 notation when an IPv4-sized prefix is used (for example, ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104). The software accepts these inputs without error but ends up trusting every IPv4 address on the internet. This allows an unauthenticated client to provide an arbitrary
X-Forwarded-For header to control the address the application reads, bypassing IP-based access control, rate limiting, geolocation, and audit logging.Recommendations
Update to version 5.1.1 or later.
Ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Fastify/Proxy-Addr