CVE-2026-43634: HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HestiaCPto a version that resolves this vulnerability.Fixed in 1.9.4 - Configuration
Update/adjust HestiaCP to only trust the CF-Connecting-IP HTTP header after verifying the request came from Cloudflare’s network; otherwise ignore the header to prevent unauthenticated IP spoofing (affects HestiaCP versions 1.2.0 through 1.9.4).
HestiaCP CF-Connecting-IP handling = verify request originates from Cloudflare before trusting CF-Connecting-IP
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43634?
CVE-2026-43634 is considered to be a high-severity vulnerability due to its potential for unauthenticated access and exploitation.
How do I fix CVE-2026-43634?
To fix CVE-2026-43634, upgrade HestiaCP to a version later than 1.9.4 that includes security patches addressing this vulnerability.
Who is affected by CVE-2026-43634?
CVE-2026-43634 affects all versions of HestiaCP from 1.2.0 to 1.9.4.
What type of vulnerability is CVE-2026-43634?
CVE-2026-43634 is an IP spoofing vulnerability that allows attackers to bypass authentication controls.
Can CVE-2026-43634 be exploited remotely?
Yes, CVE-2026-43634 can be exploited remotely by unauthenticated attackers using the CF-Connecting-IP HTTP header.