{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-54738",
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "state": "PUBLISHED",
        "assignerShortName": "GitHub_M",
        "dateReserved": "2026-06-15T23:07:33.233Z",
        "datePublished": "2026-08-19T20:27:45.162Z",
        "dateUpdated": "2026-08-19T20:27:45.162Z"
    },
    "containers": {
        "cna": {
            "title": "Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-799",
                            "lang": "en",
                            "description": "CWE-799: Improper Control of Interaction Frequency",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "LOW",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    }
                }
            ],
            "references": [
                {
                    "name": "https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2hrg-7x4g-9vpg",
                    "tags": [
                        "x_refsource_CONFIRM"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2hrg-7x4g-9vpg"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/pull/6574",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/pull/6574"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/pull/6575",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/pull/6575"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/commit/41513c89ceecee719bff05acfe613e3b1e85f23c",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/commit/41513c89ceecee719bff05acfe613e3b1e85f23c"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/commit/8b5b2aa78417b53ff3622c01f5bed2f1590f3b82",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/commit/8b5b2aa78417b53ff3622c01f5bed2f1590f3b82"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/releases/tag/0.19.19",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/releases/tag/0.19.19"
                },
                {
                    "name": "https://github.com/LemmyNet/lemmy/releases/tag/1.0.0-beta.1",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://github.com/LemmyNet/lemmy/releases/tag/1.0.0-beta.1"
                },
                {
                    "name": "https://join-lemmy.org/news/2026-06-09_-_Lemmy_Release_v0.19.19",
                    "tags": [
                        "x_refsource_MISC"
                    ],
                    "url": "https://join-lemmy.org/news/2026-06-09_-_Lemmy_Release_v0.19.19"
                }
            ],
            "affected": [
                {
                    "vendor": "LemmyNet",
                    "product": "lemmy",
                    "versions": [
                        {
                            "version": "< 0.19.19",
                            "status": "affected"
                        },
                        {
                            "version": ">= 1.0.0-alpha.5, < 1.0.0-beta.1",
                            "status": "affected"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
                "shortName": "GitHub_M",
                "dateUpdated": "2026-08-19T20:27:45.162Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $proxy_add_x_forwarded_for instead of $remote_addr, which appends the real client address to an X-Forwarded-For value supplied by the client. An unauthenticated attacker can therefore place a different spoofed address first on each request and receive a new rate-limit bucket, bypassing limits on POST /api/v4/account/auth/register, POST /api/v4/account/auth/login, POST /api/v4/post, POST /api/v4/comment, GET /api/v4/search, POST /api/v4/image, and POST /api/v4/account/import_settings. This permits excessive account creation, brute-force attempts, spam, scraping, uploads, and repeated imports. This issue is fixed in versions 0.19.19 and 1.0.0-beta.1."
                }
            ],
            "source": {
                "advisory": "GHSA-2hrg-7x4g-9vpg",
                "discovery": "UNKNOWN"
            }
        }
    }
}