Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Halis Duraki

#25873of 53,635
9.8Total CVSS
Vulnerabilities · 1
PT-2026-5492
9.8
2026-01-30
Unknown · Crystal Shard Http-Protection · CVE-2020-37056
**Name of the Vulnerable Software and Affected Versions** Crystal Shard http-protection version 0.2.0 **Description** The software contains an IP spoofing issue that allows attackers to bypass protection middleware. This is achieved by manipulating request headers to hardcode consistent IP values across the `X-Forwarded-For`, `X-Client-IP`, and `X-Real-IP` headers, circumventing security checks and potentially gaining unauthorized access. **Recommendations** Update to a newer version that contains a fix for this vulnerability.