VYPR

megaease_easeprobe-unvalidated-X-Forwarded-For-header

by BiBi8BoBo

CVEs (1)

  • CVE-2026-82815HigAug 31, 2026
    risk 0.47cvss 7.3epss

    A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated…