mega-fence_project CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

mega-fence_project vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to mega-fence_project, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-65328 Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without validating a trusted proxy chain. An attacker can supply an arbitrary XFF value in a remote request to spoof the client IP, which is then propagated to security-relevant state (e.g., WG_CLIENT_IP cookie). Deployments that rely on this value for IP allowlists may be bypassed. [email protected] 6.5 0.06% 2026-01-05 2026-01-30
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence