—
DRUPAL-CONTRIB-2025-111
Details
This module allows you to specify an HTTP header name to determine the client's IP address.
The module doesn't sufficiently handle all cases under the scenario if Drupal Core settings `$settings['reverse_proxy']` is set to TRUE and `$settings['reverse_proxy_addresses']` is configured.
This vulnerability allows an attacker to spoof a request IP address (as Drupal sees it), potentially bypassing a variety of controls.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/reverse_proxy_header
Introduced in:
0Fixed in: 1.1.2Upgrade drupal/reverse_proxy_header to 1.1.2 or newer (ecosystem packagist:https://packages.drupal.org/8).