HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-100390 — Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the...

·Source: NIST NVD

Updated:

Executive Summary

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

Analysis

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. CVSS Score: 7.4. Published: 2026-09-25T21:17:22.637.

Indicators of Compromise (1)

CVE (1)
CVE-2026-100390
Source Attribution

Originally published by NIST NVD on Sep 25, 2026. Verified by: NIST.

Related Threats