CVE-2026-108162 | smp46 Pingvin Share X up to 1.21.x Proxy Header backend/src/main.ts X-Forwarded-For authentication bypass
A vulnerability categorized as critical has been discovered in smp46 Pingvin Share X up to 1.21.x. This issue affects some unknown processing of the file backend/src/main.ts of the component Proxy Header Handler. Executing a manipulation of the argument X-Forwarded-For can lead to authentication bypass using alternate channel.
This vulnerability is registered as CVE-2026-108162. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More