---
id: CVE-2026-84476
title: >-
  WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and
  X-Forwarded-For headers, allowing attackers to spoof the client address used
  by enforceRateLimit()
summary: >-
  WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and
  X-Forwarded-For headers, allowing attackers to spoof the client address used
  by enforceRateLimit(). Attackers can rotate the header value per request to
  bypass …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-290
published: '2026-09-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84476'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-gg65-574p-h4wc'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-authentication-bypass-via-x-real-ip-header
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-gg65-574p-h4wc'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00261
epssPercentile: 0.18247
ingestedAt: '2026-09-08T21:11:12.289Z'
---

## Overview

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
