Bug 2533602 (CVE-2026-90711) - CVE-2026-90711 proxy-addr: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Summary: CVE-2026-90711 proxy-addr: proxy-addr vulnerable to IP spoofing via IPv4-mapp...
Keywords:
Status: NEW
Alias: CVE-2026-90711
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2547483 2547484 2547485 2547486 2547487 2547489 2547490 2547491 2547493 2547496 2547497 2547488 2547492
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-15 06:41 UTC by OSIDB Bzimport
Modified: 2026-10-07 14:50 UTC (History)
131 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-15 06:41:49 UTC
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.


Note You need to log in before you can comment on or make changes to this bug.