CVE-2025-65328
MEDIUMmega-fence < 25.1.914 - IP Spoofing via X-Forwarded-For Header
Title source: llmDescription
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof the client IP, which is then propagated to security-relevant state (e.g., WG_CLIENT_IP cookie). Deployments that rely on this value for IP allowlists may be bypassed.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://raw.githubusercontent.com/p1aintext/CVE/main/CVE-2025-65328.md
Scores
CVSS v3
6.5
EPSS
0.0023
EPSS Percentile
13.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-807
Status
published
Products (1)
mega-fence_project/mega-fence
< 25.1.914
Published
Jan 05, 2026
Tracked Since
Feb 18, 2026