← Back to CVE List
CVE-2026-108555NVD
Vulnerability Summary
PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer._setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files.
CVSS v4.0 Base Metrics — Score 2.3 (LOW)
Attack VectorNetwork
Attack ComplexityHigh
Attack RequirementsPresent
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.2 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- schlagmichdoch PairDrop <= 1.11.2
- schlagmichdoch PairDrop 1.11.2
External References
- https://github.com/schlagmichdoch/PairDrop/issues/510
- https://github.com/schlagmichdoch/PairDrop
- https://github.com/schlagmichdoch/PairDrop/blob/4862ba3067be1a0f2e0d1e94861dc9200b5bfeea/server/peer.js#L44-L54
- https://github.com/schlagmichdoch/PairDrop/blob/4862ba3067be1a0f2e0d1e94861dc9200b5bfeea/server/ws-server.js#L312-L314
- https://www.vulncheck.com/advisories/pairdrop-through-1.11.2-ip-spoofing-via-cf-connecting-ip-header