CVE-2026-100390
published 2026-09-25CVE-2026-100390: Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers…
PriorityP353high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.29%
19.7th percentile
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tobychui | zoraxy | 3.2.3 – 3.3.4 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.09.1CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers.
ghsa_unreviewed·2026-09-25
CVE-2026-100390 [CRITICAL] CWE-290 Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers.
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
VulDB
tobychui Zoraxy up to 3.3.4 RemoteAddr access control (EUVD-2026-87327)
vuldb·2026-09-25·CVSS 7.4
CVE-2026-100390 [HIGH] tobychui Zoraxy up to 3.3.4 RemoteAddr access control (EUVD-2026-87327)
A vulnerability was found in tobychui Zoraxy up to 3.3.4. It has been declared as critical. This issue affects some unknown processing. Executing a manipulation of the argument RemoteAddr can lead to improper access controls.
This vulnerability appears as CVE-2026-100390. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/tobychui/zoraxyhttps://github.com/tobychui/zoraxy/blob/v3.3.4/src/mod/auth/sso/forward/util.go#L127-L142https://github.com/tobychui/zoraxy/commit/56bb3e5abb83eae42a64203028d73a001d6096c4https://github.com/tobychui/zoraxy/pull/1264https://www.vulncheck.com/advisories/zoraxy-3.2.3-through-3.3.4-client-ip-spoofing-via-x-forwarded-for-ipv6
2026-09-25
Published