Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in a Fastify plugin used for determining client IP addresses behind trusted proxies. Improperly configured trust subnets allowed unauthenticated users to spoof client IP addresses, potentially bypassing security controls like access limits and logging. The issue has been fixed in recent versions.
- Attackers can spoof client IP addresses.
- This bypasses access controls and logging.
- Verify plugin configuration and update if needed.
Attack Path
How an attacker could exploit the issue
An attacker can compromise an application by exploiting a flaw in how a Fastify plugin processes trusted IP address ranges. By sending a specially crafted request with an incorrect IPv4-mapped IPv6 subnet in a trust configuration, an attacker can trick the plugin into trusting any IP address. This allows them to bypass security controls that rely on the client's actual IP address.
- Requires network access.
- Triggers via crafted proxy configuration.
- Undermines IP-based security controls.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, applications using `@fastify/proxy-addr` could be vulnerable to IP address spoofing due to an improperly configured trust subnet. This could allow unauthenticated clients to manipulate the `X-Forwarded-For` header, bypassing IP-based access controls, rate limiting, geolocation, and audit logging mechanisms.
- Application IP address data at risk.
- Clients send spoofed X-Forwarded-For headers.
- Bypasses IP-based security controls.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts applications using the `@fastify/proxy-addr` plugin, likely managed by application owners and platform teams responsible for Fastify deployments. The first practical step is to inventory all instances of this plugin, determine their exposure and criticality, and identify the accountable owner for each.
- Application owners should verify usage.
- Confirm reachability and business criticality first.
- Plan remediation based on validated risk.