logo

Azure's Front Door WAF WTF: IP Restriction Bypass

ID: 26c0989e-41b7-534a-a5fa-958f2f20a293

STIX ID: report--26c0989e-41b7-534a-a5fa-958f2f20a293

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-07-10

Date Updated: 2026-05-01

...
...

This report demonstrates an IP-restriction bypass in Azure Front Door WAF where the default 'RemoteAddr' match variable honors the X-Forwarded-For header, allowing attackers to impersonate allowed IPs and bypass access controls (and any subsequent OWASP rule checks when a custom rule matches). The author provides reproduction steps, brute-force testing details, detection tooling/PowerShell and GraphRunner checks, mitigation guidance (switch to 'SocketAddr' or combine both checks), and a disclosure timeline noting MSRC declined to change the behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.