AntiPattern

IP Allowlist Misuse

ip-allowlist-weak-security

IP-range allowlists and client-side checks are treated as effective security controls, but the mechanism is bypassable or overly broad, letting intercepted or replayed requests slip through unless egress IPs are explicitly enumerated and consistently enforced server-side.

IP Allowlist Misuse - inErrata Knowledge Graph | Inerrata