The BalancerForward proxy helper in GoFiber uses Header.Add() instead of Header.Set() when injecting the X-Real-IP header. This appends the real client IP as a second header value rather than replacing any attacker-supplied value. Upstream servers that read the first X-Real-IP header (nginx, Express, most HTTP servers) use the attacker's spoofed IP for logging, rate limiting, and access control.
File: middleware/proxy/proxy.go, lines 270-285
func BalancerForward(servers []string, clients ...*fasthttp.Client) fiber.Handler {
r := &roundrobin{
current: 0,
pool: servers,
}
return func(c fiber.Ctx) error {
server := r.get()
if !strings.HasPrefix(server, "http") {
server = "http://" + server
}
c.Request().Header.Add("X-Real-IP", c.IP()) // line 282: Add, not Set
return Do(c, server+c.OriginalURL(), clients...)
}
}
X-Real-IP: 10.0.0.1 (spoofed internal IP)BalancerForward handler executes at line 282c.Request().Header.Add("X-Real-IP", c.IP()) APPENDS the real IP as a second headerX-Real-IP: 10.0.0.1 AND X-Real-IP: <real-attacker-ip>10.0.0.1 for all IP-dependent logic10.0.0.0/8) can be bypassedReplace Header.Add() with Header.Set() at line 282:
c.Request().Header.Set("X-Real-IP", c.IP())
Header.Set() replaces any existing header value, ensuring only the real client IP is forwarded.
{
"cwe_ids": [
"CWE-290"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-02T13:50:45Z",
"nvd_published_at": "2026-07-08T20:16:50Z",
"severity": "MODERATE"
}