A severe proxy-addr IP spoofing flaw, tracked as CVE-2026-90711 with a CVSS score of 9.1 (Critical · CVSSv3), affects popular Node.js applications by allowing unauthenticated users to bypass critical network controls through client IP address spoofing. This misconfiguration vulnerability occurs when administrators configure trust subnets using IPv4-mapped IPv6 addresses with short prefixes, causing the application to blindly trust every client as a valid proxy and extract arbitrary IP addresses from the X-Forwarded-For HTTP header. The proxy-addr module operates inside thousands of Node.js servers, including popular web frameworks like Express, making it a critical vulnerability affecting proxy-addr versions This critical vulnerability affects all proxy-addr versions prior to 2 that affects all proxy-addr versions prior to 2.0.8. Industry estimates show developers download this npm package over 364 million times every month, threatening massive portions of the modern web if attackers successfully forge their IP addresses and bypass network access control lists, defeat rate limiting, bypass geolocation restrictions, or corrupt security audit logs.
We recommend you to update proxy-addr to version 2.0.8.[/subscribe_to_unlock_form]
A severe proxy-addr IP spoofing flaw, tracked as CVE-2026-90711 with a CVSS score of 9.1 (Critical · CVSSv3), affects popular Node.js applications by allowing unauthenticated users to bypass critical network controls through client IP address spoofing. This misconfiguration vulnerability occurs when administrators configure trust subnets using IPv4-mapped IPv6 addresses with short prefixes, causing the application to blindly trust every client as a valid proxy and extract arbitrary IP addresses from the X-Forwarded-For HTTP header. The proxy-addr module operates inside thousands of Node.js servers, including popular web frameworks like Express, making it a critical vulnerability affecting proxy-addr versions This critical vulnerability affects all proxy-addr versions prior to 2 that affects all proxy-addr versions prior to 2.0.8. Industry estimates show developers download this npm package over 364 million times every month, threatening massive portions of the modern web if attackers successfully forge their IP addresses and bypass network access control lists, defeat rate limiting, bypass geolocation restrictions, or corrupt security audit logs.
We recommend you to update proxy-addr to version 2.0.8.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]