CVE-2026-56682 | decolua 9Router up to 0.5.5 Login Limiter loginLimiter.js getClientIp/checkLock/recordFail X-9r-Real-Ip access control

SecurityVulns

A vulnerability was found in decolua 9Router up to 0.5.5. It has been declared as problematic. This affects the function getClientIp/checkLock/recordFail of the file src/lib/auth/loginLimiter.js of the component Login Limiter. Executing a manipulation of the argument X-9r-Real-Ip can lead to improper access controls.

This vulnerability is handled as CVE-2026-56682. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More