CRITICAL 9.1 NVD

CVE-2026-100390

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers conn

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.

References

Published: 2026-09-25 · Source: NVD · Feed updated: 2026-09-25
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-25 via NVD.

Risk Timeline

CVE Disclosed2026-09-25 · -1 days ago

Remediation Resources

vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.