CVE-2025-66482 affects Misskey, an open-source federated social media platform, allowing attackers to bypass IP rate limiting by forging X-Forwarded-For headers when an untrusted or no reverse proxy is used. This vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity that can lead to limited integrity and availability impacts. While a fix was introduced in version 2025.9.1 with the 'trustProxy' option, an insecure default value persisted until version 2025.12.0-alpha.2. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.1.0, < 2025.12.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:*:*:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:13.0.0:-:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:13.0.0:beta16:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:13.0.0:beta21:*:*:*:*:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:misskey:misskey:13.0.0:beta22:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.