---
id: GO-2026-5982
aliases:
  - GHSA-pqg7-v6wh-3pfp
title: >-
  TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied
  requests to backend services in github.com/almeidapaulopt/tsdproxy
summary: >-
  TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied
  requests to backend services in github.com/almeidapaulopt/tsdproxy
severity: none
vendor: almeidapaulopt
product: github.com/almeidapaulopt/tsdproxy
ecosystem: go
affected:
  - github.com/almeidapaulopt/tsdproxy
published: '2026-07-17'
updated: '2026-07-21'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-5982'
references:
  - url: >-
      https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-pqg7-v6wh-3pfp
  - url: >-
      https://github.com/almeidapaulopt/tsdproxy/commit/e8200b7947719e5e7fbbbdb9c34f459a4c285e77
tags:
  - osv
  - go
ingestedAt: '2026-07-22T15:33:23.783Z'
---

## Overview

TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy

## Affected packages

- `github.com/almeidapaulopt/tsdproxy`

## Remediation

Refer to the advisory for the patched release.
