Skip to content

Trusted-proxy client IP parsing lets callers bypass API rate limits #314

Description

@Calmingstorm

Defect

src/health/server.py:82-95 trusts the left-most X-Forwarded-For segment verbatim whenever the immediate peer matches web.trusted_proxies. It neither validates the segment as an IP address nor walks the forwarding chain from the trusted side. The returned string is then used as the rate-limit bucket key at src/health/server.py:415-423 and persisted as the actor IP at src/health/server.py:530-539.

Concrete failure sequence

  1. Configure the dashboard behind a trusted reverse proxy that preserves/appends an incoming X-Forwarded-For header.
  2. A caller sends more than 120 /api/ requests in one minute, changing the first header segment on every request (arbitrary strings are accepted).
  3. The proxy appends the real client address and forwards each request from its configured trusted peer.
  4. _client_ip() returns the caller-controlled first segment each time.
  5. _make_rate_limit_middleware() creates a fresh bucket for every request, so the documented 120-request limit is never reached. _make_web_audit_middleware() also records the spoofed value instead of the client address.

Malformed, empty, or ambiguous forwarding headers similarly should not become identity keys. Parse and validate forwarded addresses, derive the client by walking the chain from the trusted proxy side (with CIDR-aware trust if CIDRs are supported), and fall back to the immediate peer for malformed or ambiguous input. Add regression coverage that rotates an attacker-supplied left-most value through a trusted proxy and still reaches one stable rate-limit bucket.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions