X-Forwarded-For Header Spoofing in 1Panel Web Control Panel
CVE-2025-66508

6.5MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-66508?

1Panel, a web-based control panel designed for Linux server management, is susceptible to an IP address spoofing vulnerability due to the misuse of Gin's default configuration. This flaw allows attackers to exploit the X-Forwarded-For header manipulation, enabling them to falsify their IP address and bypass existing IP-based access controls. By sending forged X-Forwarded-For requests, attackers can exploit security measures relying on ClientIP, effectively undermining the integrity of API whitelists and access restrictions. The vulnerability has been addressed in version 2.0.14, emphasizing the importance of maintaining updated software to protect against such threats.

Affected Version(s)

1Panel < 2.0.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.