Skip to content

[Aikido] Fix critical issue in proxy-addr via minor version upgrade from 2.0.7 to 2.0.8 - #333

Merged
Overtorment merged 1 commit into
masterfrom
fix/aikido-security-update-packages-118426623-iaf8
Sep 18, 2026
Merged

Overtorment merged 1 commit into
masterfrom
fix/aikido-security-update-packages-118426623-iaf8

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade proxy-addr to fix critical IPv4-mapped IPv6 prefix validation vulnerability that allows unauthenticated clients to bypass IP-based access control and rate limiting.

✅ There are no breaking changes

✅ 1 CVE resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-101201
🚨 CRITICAL
[proxy-addr] Accepts undersized IPv4-mapped IPv6 trust subnets, allowing unauthenticated clients to spoof X-Forwarded-For headers and bypass IP-based access controls, rate limiting, and audit logging.
🤖 Remediation details

Fix critical security vulnerability in proxy-addr (AIKIDO-2026-101201)

Short summary

This PR remediates a critical vulnerability in the transitive dependency proxy-addr (versions >=1.1.0 <=2.0.7). The fix is a lockfile-only change to package-lock.json; no package.json manifest edits were required.

proxy-addr

proxy-addr is pulled in transitively by express (declared as ~2.0.7), which is a direct dependency in the root package.json. The tilde range ~2.0.7 already permits patch-level updates through 2.0.8, so the lockfile entry was simply stale. Running npm update proxy-addr --package-lock-only refreshed the resolved version from 2.0.7 to 2.0.8 without any manifest changes, parent bumps, or overrides. Version 2.0.8 is the patched release that closes the critical vulnerability affecting all proxy-addr releases from 1.1.0 through 2.0.7.

Version changes

Package From To Why updated
proxy-addr 2.0.7 2.0.8 Lockfile refresh only — patched version satisfies existing ~2.0.7 range declared by express

@Overtorment
Overtorment merged commit bf7ac1e into master Sep 18, 2026
6 checks passed
@Overtorment
Overtorment deleted the fix/aikido-security-update-packages-118426623-iaf8 branch September 18, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant