Bump transitive proxy-addr to 2.0.8 (CVE-2026-90711)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 72/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- express, nodejs, typescript
调研方向
从 package.json 开始,那里已有的 pnpm overrides 配置块固定了 serialize-javascript;在其中添加一条 proxy-addr 条目,然后运行 pnpm install 以刷新 pnpm-lock.yaml。仅为了了解上下文,查看 src/controllers/admin/post-settings-restore-controller.ts:21 和 patch-settings-controller.ts:73 处的请求 IP 读取逻辑,因为此修复不会改动它们。完成标准是 pnpm why proxy-addr 解析为 2.0.8,并且 frozen 安装通过。
由索引模型根据 Issue 内容生成。
描述
Summary
[email protected] resolves into this tree via [email protected] — see pnpm-lock.yaml, [email protected] at the dependency edge under express. That version is affected by CVE-2026-90711 (GHSA-jqcg-44mw-7w3h, Aikido AIKIDO-2026-101201, scored critical), fixed in 2.0.8.
The defect
proxy-addr accepts an IPv4-mapped IPv6 trust subnet with an IPv4-sized prefix — ::ffff:10.0.0.0/8 instead of ::ffff:10.0.0.0/104 — and treats that as trusting every IPv4 address. The socket peer is then counted as hop 0, so any unauthenticated client can set X-Forwarded-For to an arbitrary address. Everything built on the resolved client IP — IP allow-lists, rate limiting, geolocation, audit logging — becomes spoofable.
Exposure here: low, but not zero
createWebApp()insrc/factories/web-app-factory.tscallsexpress()and never setstrust proxy, so Express keeps its default offalseandreq.ipis the socket peer. The relay's own client-IP logic does not go through Express at all: it usesgetRemoteAddress()/isTrustedProxy()insrc/utils/http.ts, which trust a forwarded header only against configured proxies — the hardening from #493.- But
request.ipis read directly insrc/controllers/admin/post-settings-restore-controller.ts:21andsrc/controllers/admin/patch-settings-controller.ts:73. In any deployment that setstrust proxyto a proxy subnet — the common pattern behind Cloudflare or nginx, and frequently written in IPv4-mapped IPv6 notation —proxy-addrbecomes load-bearing for those paths, and that is precisely the configuration this CVE turns into an authentication bypass.
Fix
[email protected] declares ~2.0.7 and [email protected] declares ^2.0.7; both already accept 2.0.8, so no framework change is needed. This repo already carries a pnpm overrides block (serialize-javascript), so it is one line:
"pnpm": { "overrides": { "proxy-addr": "^2.0.8" } }
then pnpm install to refresh the lockfile and pnpm why proxy-addr to confirm 2.0.8 resolves.
Not urgent for a default deployment, but it is a zero-risk bump that closes the class outright, and cheaper now than reasoning about each operator's proxy configuration later.
Advisory: https://intel.aikido.dev/cve/AIKIDO-2026-101201 · Upstream: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h
One pnpm note, from doing this on
cameri/akkadian-agentminutes after filing. At the[email protected]this repo pins, thepackage.jsonpnpm.overridesfield above works — the existingserialize-javascriptoverride proves it (declared>=7.0.3 <8, resolved 7.0.5 in the lockfile). But pnpm 11 no longer reads that field at all; it warnsThe "pnpm" field in package.json is no longer read by pnpm ... "pnpm.overrides"and ignores the setting. My first attempt there failed that way, and what caught it waspnpm installrefusing withERR_PNPM_LOCKFILE_CONFIG_MISMATCH— a frozen install compares the override config against the lockfile, so a silently-ignored override cannot reach a commit. When this repo moves to pnpm 11, the overrides block has to move topnpm-workspace.yaml(akkadian-agent got one that way, entry written in the samepkg@range: '>=version'style as its existing list).
- 主要语言
- TypeScript
- 星标
- 829
- 派生
- 234
- 平均合并
- 4 天 5 小时
- 30 天内合并 PR
- 22
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
cameri/nostream 的其他 Issue
-
validateSettings() doesn't validate rateLimits[].period — zero period silently degrades to a 1ms backoff hint可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
feat(nip77): negentropy reconciliation core for the PostgreSQL backend可能已有人在做 @Priyanshubhartistm 于 2 天前认领。 未关闭enhancement
cameri/nostream#801 · 已指派 1 人 ·
维护者通常 1 天内回复
-
feat(admin): bounded NIP-66 probe history and Network Health timeline可能已有人在做 @Ferryx349 于 2 天前认领。 未关闭Admin Console enhancement
cameri/nostream#800 · 已指派 1 人 ·
维护者通常 1 天内回复
-
Store relay settings overrides in PostgreSQL (SETTINGS_BACKEND=db)可能已有人在做 @Ferryx349 于 36 天前认领。 未关闭enhancement
cameri/nostream#757 · 已指派 1 人 ·
维护者通常 1 天内回复
-
feat(nip85): Web-of-Trust spam mitigation engine可能重新可做 @Ferryx349 于 66 天前认领,目前没有进行中的 PR。 未关闭enhancement
cameri/nostream#720 · 已指派 1 人 ·
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
NousResearch/hermes-agent#136483 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
factory-active factory-automatic task-bug-reproduction-success task-identify-harness-labels-done task-identify-issue-type-done
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
[Bug]: Web chat input doesn't regain focus after a reply finishes可能已有人在做 @GaijinSystems 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 76/100
zeroclaw-labs/zeroclaw#11658 ·
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 75/100
babylonlabs-io/babylon-toolkit#2711 ·
维护者通常 1 天内回复