VDB
CVE-2025-66508
CVE-2025-66508
PUBLISHED
CVSS 6.5 MEDIUM
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (TrustedProxies = 0.0.0.0/0), allowing any client to spoof the X-Forwarded-For header. Since all IP-based access controls (AllowIPs, API whitelists, localhost-only checks) rely on ClientIP(), attackers can bypass these protections by simply sending X-Forwarded-For: 127.0.0.1 or any whitelisted IP. This renders all IP-based security controls ineffective. This issue is fixed in version 2.0.14.
EPSS 0.25% · 15.2th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.25%
15.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | 1Panel-dev/1Panel/agent | 0 |
| 1Panel-dev | 1Panel | < 2.0.14 |
| github.com | 1Panel-dev/1Panel | 0 |
| fit2cloud | 1panel | 0 |
Timeline
- Dec 3, 2025 CVE ID Reserved
- Dec 8, 2025 CVE Published
- Dec 9, 2025 EPSS Score
- Dec 14, 2025 EPSS Score
- Dec 17, 2025 CVE Updated
- Dec 18, 2025 EPSS Score
- Dec 23, 2025 EPSS Score
- Dec 27, 2025 EPSS Score
- Jan 1, 2026 EPSS Score
- Jan 6, 2026 EPSS Score
- Jan 10, 2026 EPSS Score
- Jan 15, 2026 EPSS Score