CRITICAL 9.1 NVD
CVE-2026-100390
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers conn
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
References
- https://github.com/tobychui/zoraxy
- https://github.com/tobychui/zoraxy/blob/v3.3.4/src/mod/auth/sso/forward/util.go#L127-L142
- https://github.com/tobychui/zoraxy/commit/56bb3e5abb83eae42a64203028d73a001d6096c4
- https://github.com/tobychui/zoraxy/pull/1264
- https://www.vulncheck.com/advisories/zoraxy-3.2.3-through-3.3.4-client-ip-spoofing-via-x-f
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-25 via NVD.
Risk Timeline
CVE Disclosed2026-09-25 · -1 days ago
Remediation Resources
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.