HIGH 8.3 GitHub
CVE-2026-56675
9router /v1 APIs has unauthenticated access via reverse proxy locality collapse
## Summary
9router treats local loopback requests as trusted and allows access to `/v1/*` without an
API key. In a documented/common reverse-proxy deployment where nginx forwards public
traffic to the backend via `127.0.0.1`, external non-`Origin` requests are misclassified as
local. This allows unauthenticated access to `/v1` APIs such as `/v1/models`, and may allow
abuse of configured upstream provider credentials depending on the enabled providers.
## Details
- **Affected version / commit:
Affected Products
- npm/9router <= 0.4.80
References
- https://github.com/advisories/GHSA-x5c9-v98j-722r
- https://github.com/decolua/9router/security/advisories/GHSA-x5c9-v98j-722r
- https://nvd.nist.gov/vuln/detail/CVE-2026-56675
- https://github.com/decolua/9router/commit/da667836cc7584bea0edd893de1d590c9ea279dc
This high severity vulnerability with a CVSS score of 8.3 was published on 2026-09-23 via GitHub. Affected: npm/9router <= 0.4.80.
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.