{"id":"GO-2026-5982","aliases":["GHSA-pqg7-v6wh-3pfp"],"title":"TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy","summary":"TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy","severity":"none","vendor":"almeidapaulopt","product":"github.com/almeidapaulopt/tsdproxy","ecosystem":"go","affected":["github.com/almeidapaulopt/tsdproxy"],"published":"2026-07-17","updated":"2026-07-21","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-5982","references":[{"url":"https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp"},{"url":"https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77"}],"tags":["osv","go"],"ingestedAt":"2026-07-22T15:33:23.783Z","slug":"GO-2026-5982","body":"## Overview\n\nTsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy\n\n## Affected packages\n\n- `github.com/almeidapaulopt/tsdproxy`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}