Skip to content

DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core - #383

Merged
moubctez merged 2 commits into
release/2.1from
standardise_client_ip
Sep 1, 2026
Merged

DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core#383
moubctez merged 2 commits into
release/2.1from
standardise_client_ip

Conversation

@moubctez

@moubctez moubctez commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This issue is for vulnerability found by our security team during cyclical penetration testing of our solution.
Once the entire process is completed, a detailed report will be published, providing all interested parties with detailed information about the tests conducted and the issues that were reported on the soon to be published dedicated web page:

https://defguard.net/pentesting/

Please follow any issue you are interested, when the issue will be closed there will be linked pull request fixing the issue.

@moubctez moubctez changed the title Standardise client IP handling DG2608-18: Client IP address is taken from attacker-controlled forwarding headers and forwarded to Defguard Core Sep 1, 2026
@moubctez
moubctez merged commit 2bc372f into release/2.1 Sep 1, 2026
3 checks passed
@moubctez
moubctez deleted the standardise_client_ip branch September 1, 2026 10:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants