{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/proxy-addr--2.0.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:proxy-addr_project:proxy-addr:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-90711"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["proxy-addr (\u003c 2.0.8)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","web-application","network-security"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe proxy-addr package (versions 1.1.0 through 2.0.7) contains a vulnerability that leads to IP spoofing when applications use specific IPv4-mapped IPv6 trust subnets. When an application configures a trust subnet using an IPv4-mapped IPv6 address with a short prefix, such as ::ffff:10.0.0.0/8 (intended to be ::ffff:10.0.0.0/104), the library incorrectly compiles the subnet as matching all IPv4 addresses rather than the specified block. This misconfiguration causes the application to treat every incoming client as a trusted proxy.\u003c/p\u003e\n\u003cp\u003eConsequently, applications relying on proxy-addr (commonly used by Express) will accept the X-Forwarded-For header provided by any unauthenticated client as the legitimate remote IP address. This flaw allows attackers to bypass IP-based access controls, rate limiting, and geolocation restrictions, while simultaneously poisoning audit logs with attacker-controlled IP addresses. The vulnerability affects any configuration where an IPv6 trust subnet includes zero leading bits, such as ::/1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass security measures dependent on the client IP address. This impacts any application using Express or other frameworks that leverage proxy-addr for IP trust decisions. If exploited, an attacker can bypass rate limiting, circumvent IP-based authentication, and mislead security monitoring systems by injecting arbitrary values into the X-Forwarded-For header. The scope is widespread for web applications that utilize complex IPv6/IPv4-mapped networking configurations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the proxy-addr package to version 2.0.8 or later immediately to patch CVE-2026-90711.\u003c/li\u003e\n\u003cli\u003eAudit existing proxy-addr trust configurations for IPv4-mapped IPv6 notation.\u003c/li\u003e\n\u003cli\u003eIf IPv4-mapped notation is required, ensure the prefix covers the full mapped marker (e.g., use ::ffff:10.0.0.0/104 instead of /8).\u003c/li\u003e\n\u003cli\u003ePrefer plain IPv4 notation (e.g., 10.0.0.0/8) for IPv4 subnets to eliminate potential parsing ambiguity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T12:45:50Z","date_published":"2026-10-06T12:45:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-proxy-addr-spoofing/","summary":"The proxy-addr package is vulnerable to IP spoofing due to improper validation of IPv4-mapped IPv6 trust subnets, allowing attackers to manipulate X-Forwarded-For headers and bypass IP-based security controls.","title":"Proxy-addr IP Spoofing via Misconfigured IPv4-mapped IPv6 Subnets","url":"https://feed.craftedsignal.io/briefs/2026-10-proxy-addr-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - Proxy-Addr (\u003c 2.0.8)","version":"https://jsonfeed.org/version/1.1"}