Spoofable forwarded client-IP headers vulnerability in Regular Labs products
CVE-2026-64875

6.5MEDIUM

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-64875?

A vulnerability has been identified in Regular Labs products where GeoIP lookups are compromised by trusting spoofable forwarded client-IP headers. This flaw may allow malicious actors to bypass GeoIP rules, potentially exposing sensitive content or functionality based on geographic location. It is crucial for users of these products to be aware of this issue and implement appropriate security measures to mitigate the risk.

Affected Version(s)

GeoIP extension for Joomla 1.0.0-6.3.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.