Neotoma Auth Bypass Vulnerability in Reverse Proxy Loopback Traffic

Vulnerability

An authentication bypass vulnerability has been identified in Neotoma versions 0.6.0 prior to 0.11.1. The issue arises when public reverse-proxied requests are received over a loopback socket without a Bearer token, leading the application to mistakenly treat these requests as local. This allows unauthenticated access to the hosted Inspector and related API, as the REST authentication middleware can incorrectly resolve such requests as coming from the local development user.

Impact

Exploitation of this vulnerability allows unauthorized access to production data through the Inspector/API on affected deployments.

Remediation

Users can upgrade to Neotoma version 0.11.1 or later to address this vulnerability. For deployments behind a trusted auth layer or reverse proxy, the loopback trust can be re-enabled with the 'NEOTOMA_TRUST_PROD_LOOPBACK=1' environment variable, after ensuring that only trusted local hops reach the Node process.

Added: May 29, 2026, 6:34 PM
Updated: May 29, 2026, 6:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.0
remediation
0.0
relevance
9.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.