VDB
Sign up
—

DRUPAL-CONTRIB-2025-111

Details

This module allows you to specify an HTTP header name to determine the client's IP address.

The module doesn't sufficiently handle all cases under the scenario if Drupal Core settings `$settings['reverse_proxy']` is set to TRUE and `$settings['reverse_proxy_addresses']` is configured.

This vulnerability allows an attacker to spoof a request IP address (as Drupal sees it), potentially bypassing a variety of controls.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/reverse_proxy_header
Introduced in: 0Fixed in: 1.1.2

Upgrade drupal/reverse_proxy_header to 1.1.2 or newer (ecosystem packagist:https://packages.drupal.org/8).

References