IP Spoofing Vulnerability in PairDrop by Schlagmichdoch
CVE-2026-108555

2.3LOW

Key Information:

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-108555?

PairDrop, up to version 1.11.2, is susceptible to an IP spoofing vulnerability in the Peer._setIP function. This flaw allows attackers to supply a forged cf-connecting-ip header, enabling them to join the discovery rooms of other networks. If an attacker is aware of the target's public IP address, they can masquerade as a local device in self-hosted instances that are not protected by Cloudflare, potentially compromising file sharing operations.

Affected Version(s)

PairDrop 0 <= 1.11.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.