<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:proxy-Addr_project:proxy-Addr:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aproxy-addr_projectproxy-addrnode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 12:45:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aproxy-addr_projectproxy-addrnode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Proxy-addr IP Spoofing via Misconfigured IPv4-mapped IPv6 Subnets</title><link>https://feed.craftedsignal.io/briefs/2026-10-proxy-addr-spoofing/</link><pubDate>Tue, 06 Oct 2026 12:45:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-proxy-addr-spoofing/</guid><description>The proxy-addr package is vulnerable to IP spoofing due to improper validation of IPv4-mapped IPv6 trust subnets, allowing attackers to manipulate X-Forwarded-For headers and bypass IP-based security controls.</description><content:encoded><![CDATA[<p>The proxy-addr package (versions 1.1.0 through 2.0.7) contains a vulnerability that leads to IP spoofing when applications use specific IPv4-mapped IPv6 trust subnets. When an application configures a trust subnet using an IPv4-mapped IPv6 address with a short prefix, such as ::ffff:10.0.0.0/8 (intended to be ::ffff:10.0.0.0/104), the library incorrectly compiles the subnet as matching all IPv4 addresses rather than the specified block. This misconfiguration causes the application to treat every incoming client as a trusted proxy.</p>
<p>Consequently, applications relying on proxy-addr (commonly used by Express) will accept the X-Forwarded-For header provided by any unauthenticated client as the legitimate remote IP address. This flaw allows attackers to bypass IP-based access controls, rate limiting, and geolocation restrictions, while simultaneously poisoning audit logs with attacker-controlled IP addresses. The vulnerability affects any configuration where an IPv6 trust subnet includes zero leading bits, such as ::/1.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to bypass security measures dependent on the client IP address. This impacts any application using Express or other frameworks that leverage proxy-addr for IP trust decisions. If exploited, an attacker can bypass rate limiting, circumvent IP-based authentication, and mislead security monitoring systems by injecting arbitrary values into the X-Forwarded-For header. The scope is widespread for web applications that utilize complex IPv6/IPv4-mapped networking configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the proxy-addr package to version 2.0.8 or later immediately to patch CVE-2026-90711.</li>
<li>Audit existing proxy-addr trust configurations for IPv4-mapped IPv6 notation.</li>
<li>If IPv4-mapped notation is required, ensure the prefix covers the full mapped marker (e.g., use ::ffff:10.0.0.0/104 instead of /8).</li>
<li>Prefer plain IPv4 notation (e.g., 10.0.0.0/8) for IPv4 subnets to eliminate potential parsing ambiguity.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>network-security</category></item></channel></rss>