GHSA-pqg7-v6wh-3pfp: TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
The HTTP reverse proxy handler in tsdproxy does not strip the X-Forwarded-For (or X-Real-IP) header from incoming requests before calling r.SetXForwarded(). This allows an authenticated Tailscale user to inject arbitrary X-Forwarded-For values that are forwarded verbatim to backend services.
// internal/proxymanager/port.go -- Rewrite function
Rewrite: func(r *httputil.ProxyRequest) {
r.SetURL(pconfig.GetFirstTarget())
r.Out.Host = r.In.Host
// Strips tsdproxy identity headers (correct)
r.Out.Header.Del(consts.HeaderID)
r.Out.Header.Del(consts.HeaderRemoteUser)
r.Out.Header.Del(consts.HeaderXForwardedUser)
// ... other identity headers deleted ...
// X-Forwarded-For is NOT deleted before SetXForwarded!
// X-Real-IP is NOT deleted at all!
r.SetXForwarded() // APPENDS client IP to attacker-controlled XFF list
},
Per Go’s httputil.ProxyRequest.SetXForwarded() documentation:
If the inbound request has an existing X-Forwarded-For header, SetXForwarded appends the inbound request’s remote address to the list.
Result when attacker sends X-Forwarded-For: 127.0.0.1:
- Backend receives: X-Forwarded-For: 127.0.0.1,
- If backend reads first element as “original client”, attacker appears as 127.0.0.1
X-Real-IP is not handled at all – if the attacker sets X-Real-IP: 127.0.0.1, it is forwarded to the backend verbatim without any overriding or stripping.
Many backend applications trust the first element of X-Forwarded-For (or X-Real-IP) for:
- IP-based access control (admin panels restricted to 127.0.0.1)
- Rate limiting tied to source IP
- Audit logging
- Geo-blocking or network-segment restrictions
This is particularly impactful in tsdproxy’s intended use case where the backend service is only accessible through tsdproxy – making the proxy’s header handling the sole enforcement point.
References
Code Behaviors & Features
Detect and mitigate GHSA-pqg7-v6wh-3pfp with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →