IP Spoofing Vulnerability in PairDrop by Schlagmichdoch
CVE-2026-108555
2.3LOW
What is CVE-2026-108555?
PairDrop, up to version 1.11.2, is susceptible to an IP spoofing vulnerability in the Peer._setIP function. This flaw allows attackers to supply a forged cf-connecting-ip header, enabling them to join the discovery rooms of other networks. If an attacker is aware of the target's public IP address, they can masquerade as a local device in self-hosted instances that are not protected by Cloudflare, potentially compromising file sharing operations.
Affected Version(s)
PairDrop 0 <= 1.11.2
