srvx is vulnerable to Improper Access Control
65
Medium Risk
The srvx server resolves X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host headers by taking the leftmost value when the trustProxy option is enabled. Because real proxies append to these headers, the leftmost entry is fully client-controlled, so a request can set an arbitrary client IP, protocol, or host. This lets an attacker spoof request.ip to bypass IP allowlists, rate limits, and geo checks, poison audit logs, and poison forwarded proto and host values used in cache keys and generated links. The fix resolves the forwarded chain hop-aware from the trusted peer inward so only values contributed by trusted proxies are honored.
You are affected if you are using a version that falls within the vulnerable range and have enabled the trustProxy option.
srvx is vulnerable to Improper Access Control in versions 0.11.22 - 0.11.22.
Upgrade the srvx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant