Vulnerability
CVE-2026-100390
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 03:35
Description
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Aliases and classifications
Authentication Bypass by SpoofingCWE-290
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 7.4
- cvss vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- cvss severity
- HIGH
Provenance
Public references
- VulnCheck Advisory: Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6
https://www.vulncheck.com/advisories/zoraxy-3.2.3-through-3.3.4-client-ip-spoofing-via-x-forwarded-for-ipv6 - product
https://github.com/tobychui/zoraxy - Pull Request #1264
https://github.com/tobychui/zoraxy/pull/1264 - technical-description
https://github.com/tobychui/zoraxy/blob/v3.3.4/src/mod/auth/sso/forward/util.go - Patch Commit
https://github.com/tobychui/zoraxy/commit/56bb3e5abb83eae42a64203028d73a001d6096c4
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.