GO-2026-5982None▾ SunlitTsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
github.com/almeidapaulopt/tsdproxyRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-pqg7-v6wh-3pfpHigh· 8.5TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
GO-2026-5969NoneTSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation