{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "0.19.19"
              },
              {
                "introduced": "1.0.0-alpha.5"
              },
              {
                "fixed": "1.0.0-beta.1"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "introduced": "87cbc2f3702bde803b313161321306a37af6ae3e"
            },
            {
              "fixed": "f6e986e7e54d456aa1ffec38f1576c5bb15e0afd"
            },
            {
              "fixed": "fe8b39b10bb70e9c0edca2df7a63c8f8d4059c98"
            },
            {
              "fixed": "41513c89ceecee719bff05acfe613e3b1e85f23c"
            },
            {
              "fixed": "8b5b2aa78417b53ff3622c01f5bed2f1590f3b82"
            }
          ],
          "repo": "https://github.com/lemmynet/lemmy",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-2hrg-7x4g-9vpg"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-799"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54738.json"
  },
  "details": "Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $proxy_add_x_forwarded_for instead of $remote_addr, which appends the real client address to an X-Forwarded-For value supplied by the client. An unauthenticated attacker can therefore place a different spoofed address first on each request and receive a new rate-limit bucket, bypassing limits on POST /api/v4/account/auth/register, POST /api/v4/account/auth/login, POST /api/v4/post, POST /api/v4/comment, GET /api/v4/search, POST /api/v4/image, and POST /api/v4/account/import_settings. This permits excessive account creation, brute-force attempts, spam, scraping, uploads, and repeated imports. This issue is fixed in versions 0.19.19 and 1.0.0-beta.1.",
  "id": "CVE-2026-54738",
  "modified": "2026-09-11T03:30:26.689040067Z",
  "published": "2026-08-19T20:27:45.162Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/LemmyNet/lemmy/releases/tag/0.19.19"
    },
    {
      "type": "WEB",
      "url": "https://github.com/LemmyNet/lemmy/releases/tag/1.0.0-beta.1"
    },
    {
      "type": "WEB",
      "url": "https://join-lemmy.org/news/2026-06-09_-_Lemmy_Release_v0.19.19"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54738.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/LemmyNet/lemmy/security/advisories/GHSA-2hrg-7x4g-9vpg"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54738"
    },
    {
      "type": "FIX",
      "url": "https://github.com/LemmyNet/lemmy/commit/41513c89ceecee719bff05acfe613e3b1e85f23c"
    },
    {
      "type": "FIX",
      "url": "https://github.com/LemmyNet/lemmy/commit/8b5b2aa78417b53ff3622c01f5bed2f1590f3b82"
    },
    {
      "type": "FIX",
      "url": "https://github.com/LemmyNet/lemmy/pull/6574"
    },
    {
      "type": "FIX",
      "url": "https://github.com/LemmyNet/lemmy/pull/6575"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo"
}