Impact
proxy‑addr incorrectly accepts IPv4‑mapped IPv6 trust subnets with ::ffff:10.0.0.0/8, and treats every IPv4 address on the internet as trusted. A client, without authentication, can supply an arbitrary X‑Forwarded‑For header and set the perceived client address, thus breaking IP‑based access control, rate limiting, geolocation, and audit logging. The weakness centers on improper input validation and trust configuration, involving CWE‑290 – Improper Authorization, CWE‑348 – Insecure Deserialization, and CWE‑697 – Use After Incorporation.
Affected Systems
The issue affects the Node.js module proxy‑addr versions 1.1.0 through 2.0.7. Users of these versions running behind trusted reverse proxies are exposed.
Risk and Exploitability
The CVSS score is 9.1, and the EPSS score is reported as < 1%, indicating that exploitation is possible but not widespread yet. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending HTTP requests with a crafted X‑Forwarded‑For header to a server that uses the vulnerable proxy‑addr module, thereby manipulating the reported client IP.
OpenCVE Enrichment