Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-682r-rv3j-v5mh

Опубликовано: 31 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 9.8

Описание

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.

EPSS

Процентиль: 16%
0.00052
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 9.8
nvd
8 дней назад

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.

EPSS

Процентиль: 16%
0.00052
Низкий

6.9 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-290