CVE-2025-66482: Misskey has a login rate limit bypass via spoofed X-Forwarded-For header

Published Dec 15, 2025
·
Updated

Summary When using an untrusted reverse proxy or not using a reverse proxy at all, attackers can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an option (trustProxy) has been added in config file to prevent this from happening. However, it is initialized with an insecure default value before version 2025.12.0, making it still vulnerable if the configuration is not set correctly.

Workaround

If you are running Misskey with a trusted reverse proxy, you should not be affected by this vulnerability.

- There is no workaround for the Misskey itself. Please update Misskey to the latest version or set up a trusted reverse proxy. - From v2025.9.1 to v2025.11.1, workaround is available. Set trustProxy: false in config file. - This is patched in v2025.12.0 by flipping default value of trustProxy to false. If you are using trusted reverse proxy and not remember you manually overrided this value, please take time to check your config for optimal behavior.

Details Fastify recommend not trusting X-Forwarded-For IPs Due to misconfiguration in https://github.com/misskey-dev/misskey/blob/develop/packages/backend/src/server/api/SigninApiService.ts#L94 attacks can spoof their IPs.

PoC

POST /api/signin-flow HTTP/1.1 Host: misskey.localhost:3123 Content-Length: 45 Content-Type: application/json Connection: keep-alive X-Forwarded-For: 127.1.1.31, 1.1.1.12

{"username":"admin", "password":"password"} !image

Impact An attacker can brute force accounts bypassing rate limiting protection.

Other sources

Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an option (trustProxy) has been added in config file to prevent this from happening. However, it is initialized with an insecure default value before version 2025.12.0-alpha.2, making it still vulnerable if the configuration is not set correctly. This is patched in v2025.12.0-alpha.2 by flipping default value of trustProxy to false. Users of a trusted reverse proxy who are unsure if they manually overode this value should check their config for optimal behavior. Users are running Misskey with a trusted reverse proxy should not be affected by this vulnerability. From v2025.9.1 to v2025.11.1, workaround is available. Set trustProxy: false in config file.

MITRE

Affected Software

38 affected componentsFixes available
npm/misskey-js>=2025.9.1<2025.12.0-alpha.2
2025.12.0-alpha.2
Misskey Misskey>=13.1.0<2025.12.0
Misskey Misskey=13.0.0
Misskey Misskey=13.0.0-beta16
Misskey Misskey=13.0.0-beta21
Misskey Misskey=13.0.0-beta22
Misskey Misskey=13.0.0-beta23
Misskey Misskey=13.0.0-beta24
Misskey Misskey=13.0.0-beta25
Misskey Misskey=13.0.0-beta26
Misskey Misskey=13.0.0-beta27
Misskey Misskey=13.0.0-beta28
Misskey Misskey=13.0.0-beta29
Misskey Misskey=13.0.0-beta30
Misskey Misskey=13.0.0-beta31
Misskey Misskey=13.0.0-beta32
Misskey Misskey=13.0.0-beta33
Misskey Misskey=13.0.0-beta34
Misskey Misskey=13.0.0-beta35
Misskey Misskey=13.0.0-beta36
Misskey Misskey=13.0.0-beta37
Misskey Misskey=13.0.0-beta38
Misskey Misskey=13.0.0-beta39
Misskey Misskey=13.0.0-beta40
Misskey Misskey=13.0.0-beta41
Misskey Misskey=13.0.0-beta42
Misskey Misskey=13.0.0-beta43
Misskey Misskey=13.0.0-rc1
Misskey Misskey=13.0.0-rc10
Misskey Misskey=13.0.0-rc11
Misskey Misskey=13.0.0-rc2
Misskey Misskey=13.0.0-rc3
Misskey Misskey=13.0.0-rc4
Misskey Misskey=13.0.0-rc5
Misskey Misskey=13.0.0-rc6
Misskey Misskey=13.0.0-rc7
Misskey Misskey=13.0.0-rc8
Misskey Misskey=13.0.0-rc9

Event History

Dec 15, 2025
Advisory Published
via GitHub·08:59 PM
Data Sourced
via GitHub·08:59 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·11:18 PM
Data Sourced
via MITRE·11:18 PM
DescriptionWeakness
Dec 16, 2025
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 AM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66482?

CVE-2025-66482 is considered a high severity vulnerability due to its potential to bypass IP rate limiting.

2

How do I fix CVE-2025-66482?

To fix CVE-2025-66482, upgrade to version 2025.12.0-alpha.2 or later and configure the 'trustProxy' option in the settings.

3

What causes CVE-2025-66482?

CVE-2025-66482 is caused by the ability to forge the X-Forwarded-For header when using an untrusted reverse proxy.

4

Who is affected by CVE-2025-66482?

CVE-2025-66482 affects users of the misskey-js package versions between 2025.9.1 and 2025.12.0-alpha.2.

5

What impacts does CVE-2025-66482 have?

CVE-2025-66482 can lead to unauthorized bypassing of rate limits, potentially allowing for abuse of services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203