Skip to content

[Aikido] Prevent IP spoofing by defaulting trust_proxy() to false - #746

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137920316-6ktf
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137920316-6ktf

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses IP spoofing vulnerabilities by changing the default behavior of the trust_proxy() function to return false, requiring explicit opt-in via the AIKIDO_TRUST_PROXY environment variable to trust forwarding headers. This prevents attackers from bypassing IP-based security controls by spoofing X-Forwarded-For and similar proxy headers. The fix affects aikido_zen/helpers/get_ip_from_request.py and its corresponding test file, with updated test cases validating that proxy headers are not trusted by default and that SSRF detection properly handles untrusted client IPs.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811707819
HIGH
get_ip_from_request() gives the configured client-IP header precedence over the socket peer whenever trust_proxy() is true. When AIKIDO_TRUST_PROXY is unset, trust_proxy() returns true, and the resolver performs no immediate-peer, trusted-proxy-range, hop-count, or forwarding-chain validation. The WSGI and ASGI adapters pass attacker-supplied headers together with the actual peer address, so a direct client-or a client behind a proxy that preserves the header-can cause the header value to become Context.remote_address. Downstream IP-based security decisions use that value as authoritative. In particular, a forged loopback or allowlisted value can satisfy IP-based route authorization, while a forged bypass-listed value skips blocking, rate limiting, firewall checks, vulnerability scanning, and SSRF reporting. Other IP-based controls can be evaded or partitioned using attacker-selected addresses. This does not bypass independent application authentication, and deployments that

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant