Critical IP Spoofing Vulnerability (CVE-2026-90711) Disclosed in Node.js 'proxy-addr' Package
A severe IP spoofing flaw, tracked as CVE-2026-90711 with a CVSS score of 9.1 (Critical), has been disclosed in the popular Node.js 'proxy-addr' package. This misconfiguration vulnerability allows unauthenticated users to bypass critical network controls by spoofing their client IP addresses, potentially affecting rate limiting and access controls in applications. Developers are urged to update the package immediately to version 2.0.8 to mitigate the risk.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai