CVE-2025-66482

EUVD-2025-203441
Misskey is an open source, federated social media platform. Attackers who use an untrusted reverse proxy or not using a reverse proxy at all can bypass IP rate limiting by adding a forged X-Forwarded-For header. Starting with version 2025.9.1, an option (`trustProxy`) has been added in config file to prevent this from happening. However, it is initialized with an insecure default value before version 2025.12.0-alpha.2, making it still vulnerable if the configuration is not set correctly. This is patched in v2025.12.0-alpha.2 by flipping default value of `trustProxy` to `false`. Users of a trusted reverse proxy who are unsure if they manually overode this value should check their config for optimal behavior. Users are running Misskey with a trusted reverse proxy should not be affected by this vulnerability. From v2025.9.1 to v2025.11.1, workaround is available. Set `trustProxy: false` in config file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
misskeymisskey
13.1.0 ≤
𝑥
< 2025.12.0
misskeymisskey
13.0.0
misskeymisskey
13.0.0:beta16
misskeymisskey
13.0.0:beta21
misskeymisskey
13.0.0:beta22
misskeymisskey
13.0.0:beta23
misskeymisskey
13.0.0:beta24
misskeymisskey
13.0.0:beta25
misskeymisskey
13.0.0:beta26
misskeymisskey
13.0.0:beta27
misskeymisskey
13.0.0:beta28
misskeymisskey
13.0.0:beta29
misskeymisskey
13.0.0:beta30
misskeymisskey
13.0.0:beta31
misskeymisskey
13.0.0:beta32
misskeymisskey
13.0.0:beta33
misskeymisskey
13.0.0:beta34
misskeymisskey
13.0.0:beta35
misskeymisskey
13.0.0:beta36
misskeymisskey
13.0.0:beta37
misskeymisskey
13.0.0:beta38
misskeymisskey
13.0.0:beta39
misskeymisskey
13.0.0:beta40
misskeymisskey
13.0.0:beta41
misskeymisskey
13.0.0:beta42
misskeymisskey
13.0.0:beta43
misskeymisskey
13.0.0:rc1
misskeymisskey
13.0.0:rc10
misskeymisskey
13.0.0:rc11
misskeymisskey
13.0.0:rc2
misskeymisskey
13.0.0:rc3
misskeymisskey
13.0.0:rc4
misskeymisskey
13.0.0:rc5
misskeymisskey
13.0.0:rc6
misskeymisskey
13.0.0:rc7
misskeymisskey
13.0.0:rc8
misskeymisskey
13.0.0:rc9
𝑥
= Vulnerable software versions