External risk intelligence

proxy-addr Trust Subnet Flaw Exposes Applications to IP Spoofing.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-90711

The affected module is a foundational component of Express, a widely used Node.js web framework. It is integrated into web applications and APIs that frequently operate as internet-facing services. Because it handles request address parsing for web traffic, it is commonly deployed in public-facing network paths.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in a Node.js module used for identifying client IP addresses behind proxies could allow unauthenticated users to spoof their origin. This could undermine security controls like access restrictions and logging. The issue is a regression in how certain IP address ranges are trusted.

  • Allows spoofing client IP addresses.
  • Impacts IP-based access and rate limiting.
  • Confirm if your applications use this module.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can reach this vulnerability by sending a specially crafted request to a web application that uses the affected Node.js module. The application must be configured with a specific type of incorrect trust subnet setting. By manipulating the `X-Forwarded-For` header, the attacker can trick the application into trusting their IP address, which can lead to various security bypasses.

  • No authentication required.
  • Malicious `X-Forwarded-For` header.
  • Bypass IP-based security controls.

Live Threat

Current exploitation, exposure, and threat context

When the `proxy-addr` module is configured with a specific, improperly formatted IPv4-mapped IPv6 trust subnet, it can incorrectly trust all IPv4 addresses. This allows any unauthenticated client to forge the `X-Forwarded-For` header, potentially impacting IP-based access controls, rate limiting, geolocation, and audit logging mechanisms.

  • Application access controls could be bypassed.
  • Arbitrary client IPs may be trusted.
  • Service integrity could be compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Node.js `proxy-addr` module's vulnerability necessitates action from application owners and platform teams responsible for web services. The first practical step is to identify all instances of `proxy-addr` within your environment, determine their exposure to external network traffic, and confirm the business criticality of the services they support. Once ownership is established, a remediation plan can be developed based on the assessed risk.

  • Application and platform teams own resolution.
  • Verify external reachability and business impact.
  • Plan upgrade or apply workarounds.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the proxy-addr Node.js module?

proxy-addr is a foundational utility in the Node.js ecosystem used to accurately identify a client's IP address when a web application sits behind a reverse proxy. It powers standard address parsing functions in the popular Express framework, ensuring that request headers are interpreted correctly to help applications maintain reliable logs, rate limits, and access controls.

What weakness does CVE-2026-90711 describe?

This vulnerability, classified as CWE-290, CWE-348, and CWE-697, occurs when the module misinterprets specific IPv4-mapped IPv6 trust subnets. By miscalculating the network prefix, the software fails to properly filter trusted proxies, unintentionally treating all incoming traffic as trusted. This allows an attacker to inject their own address into request headers, effectively bypassing security checks that rely on IP identity.

Does my application's traffic trigger this vulnerability?

This bug is only triggered if your application is configured to trust subnets using the specific, improperly formatted IPv4-mapped IPv6 notation mentioned in the advisory. Simply using the proxy-addr module does not make you vulnerable; the issue specifically requires this flawed subnet configuration to enable an attacker to spoof their origin via the X-Forwarded-For header.

Why is this CVE significant for internet-facing systems?

According to Halo Surface Signal, this module is frequently deployed in public-facing network paths. If your application is internet-facing and uses an affected subnet configuration, attackers can easily bypass IP-based restrictions, rate limiting, and geolocation controls. Because the vulnerability allows unauthenticated attackers to manipulate the perceived source of their requests, it poses a notable risk to services relying on IP-based security.

How do I start addressing CVE-2026-90711?

Begin by auditing your Node.js projects to see if they include proxy-addr versions 1.1.0 through 2.0.7 and check their trust subnet configurations. If you use the affected IPv4-mapped IPv6 notation, either upgrade to version 2.0.8 or switch to plain IPv4 notation for your trust settings. Prioritize systems that face the public internet or enforce strict IP-based access controls.

References