Description
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. The plugin inherited this defect from the upstream proxy-addr module (CVE-2026-90711). The issue is fixed in @fastify/proxy-addr 5.1.1, and users should upgrade to 5.1.1 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: IP spoofing and access‑control bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability occurs when @fastify/proxy‑addr interprets a trust subnet written in IPv4‑mapped IPv6 designation but with an incorrect network mask, such as ::ffff:10.0.0.0/8. The plugin nevertheless accepts the subnet without error and treats every IPv4 address on the Internet as trustworthy. As a result an unauthenticated client can supply an arbitrary X‑Forwarded‑For header and seize control of the IP address that the application records in request.ip and request.ips. This failure of proper validator logic falls in the categories of erroneous authentication, logical flaw in trust enforcement and errors in the representation of address spaces. The consequence is the loss of IP‑based access control, rate limiting, geolocation lookup and audit‑logging accuracy, effectively allowing an attacker to bypass security controls that depend on the client’s source address.

Affected Systems

All installations of the @fastify/proxy‑addr Fastify plugin from version 3.0.0 up to and including 5.1.0 are affected. These versions are employed by Fastify web applications that depend on the plugin to determine request provenance behind trusted reverse proxies. When configured with a trust subnet that uses IPv4‑mapped IPv6 notation and an incorrect prefix length (for example ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104), the plugin is present in the affected branch of the code base.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical severity. The EPSS score of less than 1 % denotes a low probability of widespread exploitation, yet the vulnerability is not included in the CISA KEV catalogue. The attack path is straightforward: an external client sends an HTTP request with a crafted X‑Forwarded‑For header to a reverse proxy that forwards traffic to the vulnerable Fastify application. Because the plugin mistakenly considers every IPv4 address trusted, the application accepts the spoofed address and reacts to it in place of the true client IP. No privileged code execution is required; the exploit only requires the ability to inject custom header data through an ordinary HTTP request.

Generated by OpenCVE AI on September 18, 2026 at 07:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @fastify/proxy‑addr to version 5.1.1 or later. This release corrects the logic that parses IPv4‑mapped IPv6 trust subnets.
  • Verify or modify any IPv4‑mapped IPv6 trust subnet definitions to use a prefix length of at least 97, or express the subnet range in plain IPv4 notation when configuring the plugin.
  • Review reverse proxy or application settings to reject or sanitize X‑Forwarded‑For headers from unauthenticated clients to prevent spoofed IP injection.

Generated by OpenCVE AI on September 18, 2026 at 07:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fastify
Fastify proxy-addr
Vendors & Products Fastify
Fastify proxy-addr

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. The plugin inherited this defect from the upstream proxy-addr module (CVE-2026-90711). The issue is fixed in @fastify/proxy-addr 5.1.1, and users should upgrade to 5.1.1 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.
Title @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Weaknesses CWE-290
CWE-348
CWE-697
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Fastify Proxy-addr
cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-17T18:39:20.231Z

Reserved: 2026-09-16T08:28:17.064Z

Link: CVE-2026-92395

cve-icon Vulnrichment

Updated: 2026-09-17T18:39:12.885Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:19:01.857

Modified: 2026-09-17T19:17:07.053

Link: CVE-2026-92395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:15:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-348

    Use of Less Trusted Source

  • CWE-697

    Incorrect Comparison