Impact
The vulnerability occurs when @fastify/proxy‑addr interprets a trust subnet written in IPv4‑mapped IPv6 designation but with an incorrect network mask, such as ::ffff:10.0.0.0/8. The plugin nevertheless accepts the subnet without error and treats every IPv4 address on the Internet as trustworthy. As a result an unauthenticated client can supply an arbitrary X‑Forwarded‑For header and seize control of the IP address that the application records in request.ip and request.ips. This failure of proper validator logic falls in the categories of erroneous authentication, logical flaw in trust enforcement and errors in the representation of address spaces. The consequence is the loss of IP‑based access control, rate limiting, geolocation lookup and audit‑logging accuracy, effectively allowing an attacker to bypass security controls that depend on the client’s source address.
Affected Systems
All installations of the @fastify/proxy‑addr Fastify plugin from version 3.0.0 up to and including 5.1.0 are affected. These versions are employed by Fastify web applications that depend on the plugin to determine request provenance behind trusted reverse proxies. When configured with a trust subnet that uses IPv4‑mapped IPv6 notation and an incorrect prefix length (for example ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104), the plugin is present in the affected branch of the code base.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. The EPSS score of less than 1 % denotes a low probability of widespread exploitation, yet the vulnerability is not included in the CISA KEV catalogue. The attack path is straightforward: an external client sends an HTTP request with a crafted X‑Forwarded‑For header to a reverse proxy that forwards traffic to the vulnerable Fastify application. Because the plugin mistakenly considers every IPv4 address trusted, the application accepts the spoofed address and reacts to it in place of the true client IP. No privileged code execution is required; the exploit only requires the ability to inject custom header data through an ordinary HTTP request.
OpenCVE Enrichment