X-Forwarded-For Header Spoofing in 1Panel Web Control Panel
CVE-2025-66508
What is CVE-2025-66508?
1Panel, a web-based control panel designed for Linux server management, is susceptible to an IP address spoofing vulnerability due to the misuse of Gin's default configuration. This flaw allows attackers to exploit the X-Forwarded-For header manipulation, enabling them to falsify their IP address and bypass existing IP-based access controls. By sending forged X-Forwarded-For requests, attackers can exploit security measures relying on ClientIP, effectively undermining the integrity of API whitelists and access restrictions. The vulnerability has been addressed in version 2.0.14, emphasizing the importance of maintaining updated software to protect against such threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1Panel < 2.0.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
