CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy
Zoraxy versions 3.2.3 through 3.3.4 contain a vulnerability in IPv6 address parsing that allows unauthenticated attackers to spoof the X-Forwarded-For header and bypass IP-based access controls.
CVE search metadata
CVE search record: CVE-2026-100390. Severity: high. CVSS: 7.4. KEV: no. Product: Zoraxy (3.2.3 - 3.3.4). Brief: CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy. Brief link: https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/
Zoraxy versions 3.2.3 through 3.3.4 are affected by a vulnerability in how the RemoteAddr field processes IPv6 addresses when setting forwarded headers. An unauthenticated attacker can exploit this flaw by initiating a request over an IPv6 connection. Due to improper parsing of the source address, the application can be forced to accept an arbitrary value provided in the X-Forwarded-For header as the legitimate source IP. This vulnerability is significant for organizations that rely on IP-based allowlisting or access control lists (ACLs) within the Zoraxy reverse proxy or the services it protects. By spoofing a trusted internal or management IP, an attacker may gain unauthorized access to restricted application endpoints or bypass secondary authentication measures that rely on network location.
Impact
The vulnerability allows for the bypass of IP-based security controls, potentially granting unauthenticated access to sensitive administrative interfaces or internal services protected by the reverse proxy. Attackers can leverage this to gain unauthorized entry to backend systems that trust the X-Forwarded-For header provided by the proxy.
Recommendation
Update Zoraxy to a version newer than 3.3.4 to remediate CVE-2026-100390. If immediate patching is not feasible, restrict external IPv6 access to the Zoraxy management interfaces or application endpoints that utilize IP-based filtering.
Mitigations
Upgrade Zoraxy to a version newer than 3.3.4
CVE-2026-100390