Skip to content

DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core - #383

Open
moubctez wants to merge 2 commits into
release/2.1from
standardise_client_ip
Open

DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core#383
moubctez wants to merge 2 commits into
release/2.1from
standardise_client_ip

Conversation

@moubctez

@moubctez moubctez commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This issue is for vulnerability found by our security team during cyclical penetration testing of our solution.
Once the entire process is completed, a detailed report will be published, providing all interested parties with detailed information about the tests conducted and the issues that were reported on the soon to be published dedicated web page:

https://defguard.net/pentesting/

Please follow any issue you are interested, when the issue will be closed there will be linked pull request fixing the issue.

@moubctez moubctez changed the title Standardise client IP handling DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant