HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-100390 — Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the...
·Source: NIST NVD
Updated:
Executive Summary
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Analysis
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. CVSS Score: 7.4. Published: 2026-09-25T21:17:22.637.