Debian Package Tracker
Register | Log in
Subscribe

node-proxy-addr

remote address filter for proxied requests - Node.js module

Choose email to subscribe with

general
  • source: node-proxy-addr (main)
  • version: 2.0.8+~cs2.3.7-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Yadd [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.0.6+~0.1.2-1
  • oldstable: 2.0.7+~cs2.3.0-1
  • stable: 2.0.7+~cs2.3.0-1
  • testing: 2.0.8+~cs2.3.7-1
  • unstable: 2.0.8+~cs2.3.7-1
versioned links
  • 2.0.6+~0.1.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.7+~cs2.3.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.8+~cs2.3.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-proxy-addr
action needed
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-21 Last update: 2026-03-21 23:01
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-90711: (needs triaging) proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-15 Last update: 2026-09-18 17:00
news
[rss feed]
  • [2026-09-19] node-proxy-addr 2.0.8+~cs2.3.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-15] Accepted node-proxy-addr 2.0.8+~cs2.3.7-1 (source) into unstable (Xavier Guimard)
  • [2026-03-24] node-proxy-addr 2.0.7+~cs2.3.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-21] Accepted node-proxy-addr 2.0.7+~cs2.3.7-1 (source) into unstable (Xavier Guimard)
  • [2021-11-28] node-proxy-addr 2.0.7+~cs2.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2021-11-26] Accepted node-proxy-addr 2.0.7+~cs2.3.0-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2020-12-26] node-proxy-addr 2.0.6+~0.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-23] Accepted node-proxy-addr 2.0.6+~0.1.2-1 (source) into unstable (Xavier Guimard)
  • [2014-10-22] node-proxy-addr 1.0.3-1 MIGRATED to testing (Britney)
  • [2014-10-12] Accepted node-proxy-addr 1.0.3-1 (source all) into unstable (Leo Iannacone)
  • [2014-07-18] node-proxy-addr 1.0.1-1 MIGRATED to testing (Britney)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.7+~cs2.3.7-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing