CWE-348— Use of Less Trusted Source
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.— MITRE CWE catalog
88 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-348page 1 of 2
- CVE-2026-48772CRITICALCVSS 10.0EG 10.02026-06-19
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. …
- CVE-2026-61682CRITICALCVSS 9.9EG 9.92026-09-18
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* ide…
- CVE-2026-44183CRITICALCVSS 9.8EG 9.82026-05-12
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, TrustedNetworkAuthenticationHandler.ResolveClientIp parses the leftmost entr…
- CVE-2024-45410CRITICALCVSS 9.8EG 9.82024-09-19
Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a…
- CVE-2022-31813CRITICALCVSS 9.8EG 9.82022-06-09
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/applicat…
- CVE-2026-97404CRITICALCVSS 9.2EG 9.22026-09-24
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone au…
- CVE-2026-92395CRITICALCVSS 9.1EG 9.12026-09-16
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6…
- CVE-2026-90711CRITICALCVSS 9.1EG 9.12026-09-15
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an…
- CVE-2026-16272CRITICALCVSS 9.1EG 9.12026-09-09
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API WHMCS Mo…
- CVE-2026-58122CRITICALCVSS 9.1EG 9.12026-07-09
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with…
- CVE-2025-59951CRITICALCVSS 9.1EG 9.12025-10-01
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the b…
- CVE-2025-48865CRITICALCVSS 9.1EG 9.12025-05-30
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows clients to remove X-Forwarded headers (except X-Forwarded-For) due to a vulnerability in how it processes hop-by-hop head…
- CVE-2026-12249CRITICALCVSS 9.0EG 9.02026-06-22
An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendo…
- CVE-2025-69240HIGHCVSS 8.8EG 8.82026-03-16
Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the…
- CVE-2024-27773HIGHCVSS 8.8EG 8.82024-03-18
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE
- CVE-2026-102275HIGHCVSS 8.2EG 8.22026-09-28
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. Thi…
- CVE-2026-9561HIGHCVSS 8.2EG 8.22026-07-14
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provide…
- CVE-2026-55641HIGHCVSS 8.2EG 8.22026-07-10
9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypass …
- CVE-2026-46415HIGHCVSS 8.2EG 8.22026-05-19
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be…
- CVE-2025-55292HIGHCVSS 8.2EG 8.22026-01-28
Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifi…
- CVE-2024-47880HIGHCVSS 8.1EG 8.12024-10-24
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the r…
- CVE-2021-21374HIGHCVSS 8.1EG 8.12021-03-26
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/TLS certificate due …
- CVE-2026-63770HIGHCVSS 7.5EG 7.52026-07-20
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request h…
- CVE-2026-64619HIGHCVSS 7.5EG 7.52026-07-20
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers withou…
- CVE-2026-59999HIGHCVSS 7.5EG 7.52026-07-08
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
- CVE-2026-43634HIGHCVSS 7.5EG 7.52026-05-19
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header wit…
- CVE-2026-35391HIGHCVSS 7.5EG 7.52026-04-06
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by th…
- CVE-2025-27913HIGHCVSS 7.5EG 7.52025-03-10
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
- CVE-2024-23105HIGHCVSS 7.5EG 7.52024-05-14
A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.
- CVE-2022-2255HIGHCVSS 7.5EG 7.52022-08-25
A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is m…
- CVE-2021-21373HIGHCVSS 7.5EG 7.52021-03-26
Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS by default. In case of error it falls back to a non-TLS U…
- CVE-2025-47424HIGHCVSS 7.1EG 7.12025-05-09
Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.
- CVE-2026-108162MEDIUMCVSS 6.5EG 6.52026-10-10
Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed…
- CVE-2026-103592MEDIUMCVSS 6.5EG 6.52026-09-30
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwa…
- CVE-2026-101277MEDIUMCVSS 6.5EG 6.52026-09-28
A security flaw has been discovered in Trusted Domain Project OpenDKIM up to 2.11.0. The impacted element is the function dkim_process_set of the file dkim.c of the component Tag Tokenizer. Performing a manipulation results in use of less …
- CVE-2026-100653MEDIUMCVSS 6.5EG 6.52026-09-26
vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to several Hugging Face artifact loads for…
- CVE-2020-37248MEDIUMCVSS 6.5EG 6.52026-06-08
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.
- CVE-2026-35507MEDIUMCVSS 6.5EG 6.52026-04-03
Shynet before 0.14.0 allows Host header injection in the password reset flow.
- CVE-2025-1245MEDIUMCVSS 6.5EG 6.52025-05-16
Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrast…
- CVE-2022-4532MEDIUMCVSS 6.5EG 6.52024-08-17
The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for …
- CVE-2022-4537MEDIUMCVSS 6.5EG 6.52023-05-09
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved fo…
- CVE-2026-40226MEDIUMCVSS 6.4EG 6.42026-04-10
In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
- CVE-2025-43918MEDIUMCVSS 6.4EG 6.42025-04-19
SSL.com before 2025-04-19, when domain validation method 3.2.2.4.14 is used, processes certificate requests such that a trusted TLS certificate may be issued for the domain name of a requester's email address, even when the requester does …
- CVE-2026-61589MEDIUMCVSS 6.3EG 6.32026-09-16
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFacto…
- CVE-2026-16732MEDIUMCVSS 6.1EG 6.12026-08-18
fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting ad…
- CVE-2026-3635MEDIUMCVSS 6.1EG 6.12026-03-23
Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and request.host getters read X-Forwarded-Proto an…
- CVE-2026-24910MEDIUMCVSS 5.9EG 5.92026-01-27
In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).
- CVE-2026-62987MEDIUMCVSS 5.8EG 5.82026-09-21
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-co…
- CVE-2026-44046MEDIUMCVSS 5.8EG 5.82026-06-19
Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules…
- CVE-2026-107271MEDIUMCVSS 5.3EG 5.32026-10-07
Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send a different forwarded address per reque…
Map vulnerabilities like CWE-348 to your infrastructure
EchelonGraph correlates every CVE — across CWE-348 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →