Comment by inigyou

1 day ago

And it's almost certainly exploitable by a client sending that same header.

Most load balancers will silently drop the real IP address header on the ingress side to avoid exactly what you are describing. That used to be a thing around 2000 - 2001 era. If you find a load balancer with that issue today open a case with their vendor.