External risk intelligence

Fastify Proxy-Addr Trust Subnet Parsing Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92395

The vulnerability affects a plugin used by web applications to handle client address determination behind reverse proxies. Applications utilizing this plugin are commonly deployed as internet-facing services, where the ability to correctly identify and trust client IP addresses is a standard requirement for public-facing web infrastructure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in a Fastify plugin used for determining client IP addresses behind trusted proxies. Improperly configured trust subnets allowed unauthenticated users to spoof client IP addresses, potentially bypassing security controls like access limits and logging. The issue has been fixed in recent versions.

  • Attackers can spoof client IP addresses.
  • This bypasses access controls and logging.
  • Verify plugin configuration and update if needed.

Attack Path

How an attacker could exploit the issue

An attacker can compromise an application by exploiting a flaw in how a Fastify plugin processes trusted IP address ranges. By sending a specially crafted request with an incorrect IPv4-mapped IPv6 subnet in a trust configuration, an attacker can trick the plugin into trusting any IP address. This allows them to bypass security controls that rely on the client's actual IP address.

  • Requires network access.
  • Triggers via crafted proxy configuration.
  • Undermines IP-based security controls.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, applications using `@fastify/proxy-addr` could be vulnerable to IP address spoofing due to an improperly configured trust subnet. This could allow unauthenticated clients to manipulate the `X-Forwarded-For` header, bypassing IP-based access controls, rate limiting, geolocation, and audit logging mechanisms.

  • Application IP address data at risk.
  • Clients send spoofed X-Forwarded-For headers.
  • Bypasses IP-based security controls.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts applications using the `@fastify/proxy-addr` plugin, likely managed by application owners and platform teams responsible for Fastify deployments. The first practical step is to inventory all instances of this plugin, determine their exposure and criticality, and identify the accountable owner for each.

  • Application owners should verify usage.
  • Confirm reachability and business criticality first.
  • Plan remediation based on validated risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the @fastify/proxy-addr plugin?

It is a utility for Fastify web applications that identifies a user's true IP address when the application sits behind a load balancer or reverse proxy. Developers rely on this tool to feed correct IP data into request.ip and request.ips properties, which are essential for features that need to know where a connection originated.

How does CVE-2026-92395 affect IP validation?

This vulnerability falls under CWE-290, CWE-348, and CWE-697. It occurs because the software misinterprets certain IPv4-mapped IPv6 address ranges in its configuration. Instead of limiting trust to a specific internal network, it mistakenly trusts every IP address on the internet, allowing unauthorized parties to control the client address your application perceives.

Do I need a crafted request to trigger this?

No. The vulnerability is triggered by an insecure trust configuration within the software itself. Once the plugin is misconfigured with an overly broad subnet, any unauthenticated network request can exploit the logic flaw. Simply sending a request with a manipulated X-Forwarded-For header allows the caller to impersonate any IP address.

Why should I care about this vulnerability?

According to Halo Surface Signal, this plugin is frequently used in internet-facing services. If your application is exposed to the public, an attacker can bypass critical security measures like rate limiting, geolocation-based access, and audit logging by spoofing their identity, potentially gaining unauthorized access to protected resources.

How do I fix this in my environment?

The primary resolution is to update to version 5.1.1 or later of the @fastify/proxy-addr plugin. If you cannot update immediately, you must modify your trust subnet configuration. Ensure that any IPv4-mapped IPv6 address uses a prefix length of 97 or greater, or switch to using simple IPv4 notation to avoid the parsing error.

References