Description
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: IP spoofing bypassing IP‑based controls
Action: Patch
AI Analysis

Impact

proxy‑addr incorrectly accepts IPv4‑mapped IPv6 trust subnets with ::ffff:10.0.0.0/8, and treats every IPv4 address on the internet as trusted. A client, without authentication, can supply an arbitrary X‑Forwarded‑For header and set the perceived client address, thus breaking IP‑based access control, rate limiting, geolocation, and audit logging. The weakness centers on improper input validation and trust configuration, involving CWE‑290 – Improper Authorization, CWE‑348 – Insecure Deserialization, and CWE‑697 – Use After Incorporation.

Affected Systems

The issue affects the Node.js module proxy‑addr versions 1.1.0 through 2.0.7. Users of these versions running behind trusted reverse proxies are exposed.

Risk and Exploitability

The CVSS score is 9.1, and the EPSS score is reported as < 1%, indicating that exploitation is possible but not widespread yet. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending HTTP requests with a crafted X‑Forwarded‑For header to a server that uses the vulnerable proxy‑addr module, thereby manipulating the reported client IP.

Generated by OpenCVE AI on September 17, 2026 at 18:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade proxy‑addr to version 2.0.8 or later.
  • If upgrading is not immediately possible, reconfigure any IPv4‑mapped IPv6 trust subnets to use a prefix length of at least 97 or express the range in plain IPv4 notation.
  • Re‑review and restrict reverse proxy trust settings so that the application does not automatically trust all IPv4 addresses; validate the configuration after making changes.

Generated by OpenCVE AI on September 17, 2026 at 18:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Proxy-addr
Proxy-addr proxy-addr
Vendors & Products Proxy-addr
Proxy-addr proxy-addr

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.
Title proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Weaknesses CWE-290
CWE-348
CWE-697
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Proxy-addr Proxy-addr
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-15T14:48:38.703Z

Reserved: 2026-09-13T09:18:12.590Z

Link: CVE-2026-90711

cve-icon Vulnrichment

Updated: 2026-09-15T14:48:33.179Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T07:16:33.683

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-90711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-348

    Use of Less Trusted Source

  • CWE-697

    Incorrect Comparison