Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-100390: Zoraxy lets attackers spoof IP to bypass access controls
CVE-2026-100390 · published 1 day ago
Summary
Versions 3.2.3 through 3.3.4 of Zoraxy do not correctly handle IPv6 addresses when processing the X-Forwarded-For header. This lets unauthenticated users send fake source IP addresses and get past IP‑based access checks. Update to a newer version or apply the vendor’s patch to fix the parsing logic.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tobychui | zoraxy | <= 3.3.4 |
Original advisory text
Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
References
- https://github.com/tobychui/zoraxy/pull/1264 issue-tracking patch
- https://github.com/tobychui/zoraxy/commit/56bb3e5abb83eae42a64203028d73a001d6096... patch
- https://github.com/tobychui/zoraxy/blob/v3.3.4/src/mod/auth/sso/forward/util.go#... technical-description
- https://github.com/tobychui/zoraxy product
- https://www.vulncheck.com/advisories/zoraxy-3.2.3-through-3.3.4-client-ip-spoofi... third-party-advisory
Severity
9.1
Critical
CVSS 3.1: 7.4 (MITRE)
Exploitation
EPSS <1%
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta