Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-100390: Zoraxy lets attackers spoof IP to bypass access controls

CVE-2026-100390 · published 1 day ago
Summary

Versions 3.2.3 through 3.3.4 of Zoraxy do not correctly handle IPv6 addresses when processing the X-Forwarded-For header. This lets unauthenticated users send fake source IP addresses and get past IP‑based access checks. Update to a newer version or apply the vendor’s patch to fix the parsing logic.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tobychui zoraxy <= 3.3.4
Original advisory text
Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Severity
9.1 Critical
CVSS 3.1: 7.4 (MITRE)
Exploitation
EPSS <1%
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-100390 · MITRE
Track software like this
Free during beta