PT-2026-5492 · Unknown · Crystal Shard Http-Protection

Halis Duraki

·

Published

2026-01-30

·

Updated

2026-01-31

·

CVE-2020-37056

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crystal Shard http-protection version 0.2.0
Description The software contains an IP spoofing issue that allows attackers to bypass protection middleware. This is achieved by manipulating request headers to hardcode consistent IP values across the X-Forwarded-For, X-Client-IP, and X-Real-IP headers, circumventing security checks and potentially gaining unauthorized access.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2020-37056

Affected Products

Crystal Shard Http-Protection