Junglewise Threat Intelligence

almeidapaulopt TsDProxy IP spoofing via X-Forwarded-For injection

Severity: high · CVSS 8.5 · Published 2026-07-14

Technologies: github.com/almeidapaulopt/tsdproxy (Go). Vendors: Go.

Executive brief

TsDProxy is a tool used to provide secure access to internal services via Tailscale. A vulnerability in how it handles web traffic allows users to fake their source IP address. This could allow an attacker to bypass security restrictions, such as admin panels that are only supposed to be accessible from specific locations, or to hide their identity in activity logs.

Technical details

The HTTP reverse proxy handler in tsdproxy's `internal/proxymanager/port.go` fails to sanitize incoming 'X-Forwarded-For' and 'X-Real-IP' headers before forwarding requests. When `r.SetXForwarded()` is called, it appends the actual client IP to any existing, attacker-supplied 'X-Forwarded-For' values rather than replacing them. An authenticated Tailscale user can inject arbitrary IP addresses into these headers to bypass IP-based access control lists (ACLs), rate limits, or geo-blocking enforced by backend applications that trust the first element of the header chain. The issue is fixed in version 2.3.5 by explicitly stripping these headers before the proxy re-adds the authoritative client IP.

Affected products

  • almeidapaulopt tsdproxy <= 2.3.4

Timeline

  • 2026-06-03: disclosed
  • 2026-07-14: advisory: GitHub Advisory published
  • 2026-07-14: patched

References

Related threats