Description
PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files.
Published: 2026-10-10
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: IP Spoofing
Action: Patch
AI Analysis

Impact

PairDrop through 1.11.2 contains an IP spoofing vulnerability in the Peer._setIP function. A remote attacker can supply a forged cf-connecting-ip header to force the application to treat the request as if it originated from a specified IP address. The result is that the attacker can join other networks' discovery rooms and appear as a local device on self-hosted instances that are not protected behind Cloudflare. This misuse is constrained to file-transfer functions but allows an attacker to impersonate a local peer.

Affected Systems

The vulnerability affects schlagmichdoch’s PairDrop software up to version 1.11.2. Any server running this version and exposing the discovery service will be susceptible, particularly when it is self-hosted and not behind a trusted reverse proxy such as Cloudflare. The flaw does not require elevated privileges on the target; it is triggered simply by sending crafted HTTP requests containing a cf-connecting-ip header.

Risk and Exploitability

The CVSS score is 2.3, indicating low overall severity. Exploitability is high as it requires only remote header tampering, which is trivial for an attacker with internet connectivity. No exploit convictions or known public exploits have been reported, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can use the flaw to spoof local peers, potentially enabling lateral movement within the discovery network or unauthorized file transfers. Given its low severity, the risk to confidentiality, integrity, or availability is limited, but it remains exploitable without restrictions.

Generated by OpenCVE AI on October 10, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PairDrop to a version that removes the vulnerable Peer._setIP behavior.
  • If an upgrade is not possible, configure the reverse proxy or application to strip or reject the cf-connecting-ip header, or validate it against known Cloudflare IP ranges.
  • Disable or restrict peer discovery for self-hosted instances, or enforce strict IP checking using the REMOTE_ADDR field.

Generated by OpenCVE AI on October 10, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files.
Title PairDrop through 1.11.2 IP Spoofing via cf-connecting-ip Header
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T14:49:39.990Z

Reserved: 2026-10-10T14:39:40.699Z

Link: CVE-2026-108555

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T15:16:58.690

Modified: 2026-10-10T15:16:58.690

Link: CVE-2026-108555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T16:30:18Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source