Client IP Spoofing Vulnerability in Zoraxy by Toby Chui
CVE-2026-100390
9.1CRITICAL
What is CVE-2026-100390?
Zoraxy versions 3.2.3 through 3.3.4 exhibit a weakness in how IPv6 addresses are parsed within the RemoteAddr field, particularly when processing forwarded headers. This flaw allows unauthenticated attackers using IPv6 connections to manipulate the X-Forwarded-For values, enabling them to spoof their actual source IP address. Consequently, this can result in the circumvention of IP-based access controls implemented by authorization providers, potentially leading to unauthorized access to sensitive resources.
Affected Version(s)
zoraxy 3.2.3 <= 3.3.4
