Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Bump transitive proxy-addr to 2.0.8 (CVE-2026-90711)

未关闭 适合新手
#780 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
领域
backend, security

调研方向

从 package.json 开始,那里已有的 pnpm overrides 配置块固定了 serialize-javascript;在其中添加一条 proxy-addr 条目,然后运行 pnpm install 以刷新 pnpm-lock.yaml。仅为了了解上下文,查看 src/controllers/admin/post-settings-restore-controller.ts:21 和 patch-settings-controller.ts:73 处的请求 IP 读取逻辑,因为此修复不会改动它们。完成标准是 pnpm why proxy-addr 解析为 2.0.8,并且 frozen 安装通过。

由索引模型根据 Issue 内容生成。

描述

Summary

[email protected] resolves into this tree via [email protected] — see pnpm-lock.yaml, [email protected] at the dependency edge under express. That version is affected by CVE-2026-90711 (GHSA-jqcg-44mw-7w3h, Aikido AIKIDO-2026-101201, scored critical), fixed in 2.0.8.

The defect

proxy-addr accepts an IPv4-mapped IPv6 trust subnet with an IPv4-sized prefix — ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104 — and treats that as trusting every IPv4 address. The socket peer is then counted as hop 0, so any unauthenticated client can set X-Forwarded-For to an arbitrary address. Everything built on the resolved client IP — IP allow-lists, rate limiting, geolocation, audit logging — becomes spoofable.

Exposure here: low, but not zero
  • createWebApp() in src/factories/web-app-factory.ts calls express() and never sets trust proxy, so Express keeps its default of false and req.ip is the socket peer. The relay's own client-IP logic does not go through Express at all: it uses getRemoteAddress() / isTrustedProxy() in src/utils/http.ts, which trust a forwarded header only against configured proxies — the hardening from #493.
  • But request.ip is read directly in src/controllers/admin/post-settings-restore-controller.ts:21 and src/controllers/admin/patch-settings-controller.ts:73. In any deployment that sets trust proxy to a proxy subnet — the common pattern behind Cloudflare or nginx, and frequently written in IPv4-mapped IPv6 notation — proxy-addr becomes load-bearing for those paths, and that is precisely the configuration this CVE turns into an authentication bypass.
Fix

[email protected] declares ~2.0.7 and [email protected] declares ^2.0.7; both already accept 2.0.8, so no framework change is needed. This repo already carries a pnpm overrides block (serialize-javascript), so it is one line:

"pnpm": { "overrides": { "proxy-addr": "^2.0.8" } }

then pnpm install to refresh the lockfile and pnpm why proxy-addr to confirm 2.0.8 resolves.

Not urgent for a default deployment, but it is a zero-risk bump that closes the class outright, and cheaper now than reasoning about each operator's proxy configuration later.


Advisory: https://intel.aikido.dev/cve/AIKIDO-2026-101201 · Upstream: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h

One pnpm note, from doing this on cameri/akkadian-agent minutes after filing. At the [email protected] this repo pins, the package.json pnpm.overrides field above works — the existing serialize-javascript override proves it (declared >=7.0.3 <8, resolved 7.0.5 in the lockfile). But pnpm 11 no longer reads that field at all; it warns The "pnpm" field in package.json is no longer read by pnpm ... "pnpm.overrides" and ignores the setting. My first attempt there failed that way, and what caught it was pnpm install refusing with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH — a frozen install compares the override config against the lockfile, so a silently-ignored override cannot reach a commit. When this repo moves to pnpm 11, the overrides block has to move to pnpm-workspace.yaml (akkadian-agent got one that way, entry written in the same pkg@range: '>=version' style as its existing list).

主要语言
TypeScript
星标
829
派生
234
平均合并
4 天 5 小时
30 天内合并 PR
22

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

cameri/nostream 的其他 Issue

查看 cameri/nostream 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。