A critical vulnerability in ProxySQL, tracked as CVE-2026-48772, allows remote attackers to spoof client source IP addresses by abusing improper parsing of HAProxy PROXY protocol v1 UNKNOWN headers. A crafted frame with appended address fields can cause ProxySQL to trust a forged IP and use it in mysql_query_rules.client_addr, stats_mysql_processlist.cli_host, and event_log, enabling access-control and routing bypass as well as misleading audit trails. The issue affects ProxySQL versions 2.0.0 through 3.0.8 and is especially dangerous because mysql-proxy_protocol_networks = '*' is the default, exposing any reachable MySQL frontend to attempted exploitation.
The flaw was reproduced in testing by sending a forged address that triggered query rules intended for a different client, demonstrating the ability to influence schema pinning, query filtering, and other IP-based controls. ProxySQL addressed the issue in version 3.0.9, which also fixed another critical pre-authentication memory-corruption bug, CVE-2026-48773. Security advisories rate CVE-2026-48772 as remotely exploitable and severe, with published scores ranging from CVSS 9.1 to 10.0, and urge organizations running 3.0.8 or earlier to upgrade immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE entry documented CVE-2026-48773 as a critical pre-authentication heap memory corruption flaw in ProxySQL versions 2.0.18 through 3.0.8. It said oversized initial MySQL or PostgreSQL packets can trigger a remote heap overflow before authentication and identified ProxySQL 3.0.9 as the patched version.
A CVE entry documented CVE-2026-48772 as affecting ProxySQL versions 2.0.0 through 3.0.8 and identified version 3.0.9 as the fix. It described the issue as remotely exploitable source-IP spoofing via malformed HAProxy PROXY protocol v1 header handling.
ProxySQL 3.0.9 was released and remediated CVE-2026-48772, the critical source-IP spoofing issue caused by malformed handling of PROXY protocol v1 `UNKNOWN` headers. The release notes urged users on 3.0.8 or earlier to upgrade.
A GitHub security advisory described a ProxySQL flaw in PROXY protocol v1 parsing that lets attackers send a `PROXY UNKNOWN` frame with forged address fields, causing spoofed client IPs to be used in ACLs, routing, and logs. The advisory said the issue was confirmed in the 3.0.x line and also present in current master.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.