CRITICAL
9.1 CVE-2026-90711 Published 15 Sept 2026
Express.js proxy-addr IP Spoofing Bug
Worried this affects your website?
Express.js proxy-addr module, used for determining client address behind proxies, is vulnerable in versions 1.1.0 through 2.0.7.
An incorrect IPv4-mapped IPv6 notation can lead to IP-based access control bypass, rate limiting evasion, and inaccurate geolocation and audit logging.
- Versions affected: 1.1.0 - 2.0.7
- Fixed in: 2.0.8
- Workaround: Use IPv4-mapped IPv6 notation with a prefix length of at least 97 or plain IPv4 notation.
Reference: CVE-2026-90711 on NVD
← Back to Security News