Client IP Spoofing Vulnerability in Zoraxy by Toby Chui
CVE-2026-100390

9.1CRITICAL

Key Information:

Vendor

Tobychui

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-100390?

Zoraxy versions 3.2.3 through 3.3.4 exhibit a weakness in how IPv6 addresses are parsed within the RemoteAddr field, particularly when processing forwarded headers. This flaw allows unauthenticated attackers using IPv6 connections to manipulate the X-Forwarded-For values, enabling them to spoof their actual source IP address. Consequently, this can result in the circumvention of IP-based access controls implemented by authorization providers, potentially leading to unauthorized access to sensitive resources.

Affected Version(s)

zoraxy 3.2.3 <= 3.3.4

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thilo Ramke
.