CWE-348: Use of Less Trusted Source
The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.
64 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-59951 — Termix' official Docker image contains an authentication bypass vulnerability
- CVE-2025-48865 — Fabio allows HTTP clients to manipulate custom headers it adds
- CVE-2024-27773 — Unitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-348: Use of Less Trusted Source
- CVE-2026-48772 — ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL
- CVE-2025-55292 — In Meshtastic, an attacker can spoof licensed amateur flag for a node
- CVE-2026-44183 — Cleanuparr: X-Forwarded-For leftmost parsing allows remote unauthenticated admin takeover when reverse-proxy mode is enabled
- CVE-2024-47880 — OpenRefine has a reflected cross-site scripting vulnerability from POST request in ExportRowsCommand
- CVE-2026-58122 — Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
- CVE-2026-16272 — Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
- CVE-2026-12249 — Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment
- CVE-2025-69240 — Header Poisoning in Raytha CMS
- CVE-2026-9561 — Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
- CVE-2026-64619 — FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
- CVE-2026-43634 — HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header
- CVE-2026-35391 — Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery
- CVE-2025-47424 — Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set,
- CVE-2024-23105 — A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2
- CVE-2026-22201 — wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
- CVE-2025-53522 — Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be
- CVE-2025-47149 — The optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If expl
Recently published
- CVE-2026-16272 — Client IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module
- CVE-2026-16732 — fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count
- CVE-2026-25552 — Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
- CVE-2026-63220 — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
- CVE-2026-50243 — 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
- CVE-2026-63770 — Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass
- CVE-2026-64619 — FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers
- CVE-2026-46415 — Caddy Defender trusted proxy client IP bypass
- CVE-2026-9561 — Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-58122 — Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing
- CVE-2026-59897 — Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
- CVE-2026-59999 — In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not
- CVE-2026-46466 — Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
- CVE-2026-57942 — LibreTranslate - IP Spoofing via X-Forwarded-For Header
- CVE-2026-54289 — Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
- CVE-2026-12249 — Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment
- CVE-2026-48772 — ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL
- CVE-2026-44046 — Apache APISIX: wolf-rbac plugin Identity Spoofing
- CVE-2020-37248 — OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS