PT-2026-93809 · Fastify · @Fastify/Proxy-Addr

·

CVE-2026-92395

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @fastify/proxy-addr versions 3.0.0 through 5.1.0
Description This plugin, used to determine a request's client address behind trusted reverse proxies, incorrectly handles trust subnets written in IPv4-mapped IPv6 notation when an IPv4-sized prefix is used (for example, ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104). The software accepts these inputs without error but ends up trusting every IPv4 address on the internet. This allows an unauthenticated client to provide an arbitrary X-Forwarded-For header to control the address the application reads, bypassing IP-based access control, rate limiting, geolocation, and audit logging.
Recommendations Update to version 5.1.1 or later. Ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92395
GHSA-8CMM-MHW6-V7XQ

Affected Products

@Fastify/Proxy-Addr