CRITICAL 9.1 CVE-2026-90711 Published 15 Sept 2026

Express.js proxy-addr IP Spoofing Bug

Worried this affects your website?

Express.js proxy-addr module, used for determining client address behind proxies, is vulnerable in versions 1.1.0 through 2.0.7.

An incorrect IPv4-mapped IPv6 notation can lead to IP-based access control bypass, rate limiting evasion, and inaccurate geolocation and audit logging.

  • Versions affected: 1.1.0 - 2.0.7
  • Fixed in: 2.0.8
  • Workaround: Use IPv4-mapped IPv6 notation with a prefix length of at least 97 or plain IPv4 notation.

Reference: CVE-2026-90711 on NVD

← Back to Security News