CVE-2024-44930: Serilog-Contrib Serilog-Enrichers-Clientinfo

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

Affected products

  • Serilog-Contrib Serilog-Enrichers-Clientinfo: before 2.1.0 (fixed in 2.1.0)

Published 2024-08-29. Last modified 2026-06-17.