Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 14, 2026
HedgeDoc: Rate-limit bypass via CF-Connecting-IP header spoofing
CVE-2026-58488
Description
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-limiting of the /login and /register routes by spoofing IP addresses. HedgeDoc instances checked for CloudFlare's cf-connecting-ip header and used that instead of the users real IP address, if the header was present even when the request did not originate from Cloudflare. This made it possible for an attacker to spam login requests or create multiple arbitrary accounts by sending another cf-connecting-ip header every few requests. The issue has been fixed in version 1.11.0.
Affected products
1Patches
Vulnerability mechanics
References
1- github.com/hedgedoc/hedgedoc/security/advisories/GHSA-2f9f-w8xq-276vmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.