proxy-addr is vulnerable to Authentication Bypass
91
Critical Risk
proxy-addr (the resolver behind Express req.ip / req.ips) accepts an IPv4-mapped IPv6 trust subnet with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104. That configuration is treated as trusting every IPv4 address, so the socket peer is considered hop 0 and any unauthenticated client can set X-Forwarded-For to an arbitrary address. That breaks IP-based access control, rate limiting, geolocation, and audit logging. The fix rejects undersized IPv4-mapped IPv6 trust prefixes so only the intended subnet is trusted.
You are affected if you are using a version that falls within the vulnerable range and configure a trusted proxy subnet in IPv4-mapped IPv6 notation with an IPv4-sized prefix.
proxy-addr is vulnerable to Authentication Bypass in versions 1.1.0 - 2.0.7.
Upgrade the proxy-addr library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.