IP Trust Vulnerability in proxy-addr Module by Node.js
CVE-2026-90711
9.1CRITICAL
What is CVE-2026-90711?
The proxy-addr module in Node.js versions 1.1.0 to 2.0.7 contains an input validation vulnerability where an incorrectly formatted IPv4-mapped IPv6 trust subnet allows unauthenticated clients to manipulate the X-Forwarded-For header. This can lead to unauthorized access, as it undermines IP-based access controls and audit logs. Users are advised to upgrade to version 2.0.8 or later and follow recommended configurations to mitigate risks.
Affected Version(s)
proxy-addr 1.1.0 < 2.0.8
proxy-addr 2.0.8
