Skip to content
Threat Feed
high advisory

CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy

Zoraxy versions 3.2.3 through 3.3.4 contain a vulnerability in IPv6 address parsing that allows unauthenticated attackers to spoof the X-Forwarded-For header and bypass IP-based access controls.

CVE search metadata

CVE search record: CVE-2026-100390. Severity: high. CVSS: 7.4. KEV: no. Product: Zoraxy (3.2.3 - 3.3.4). Brief: CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy. Brief link: https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/

Zoraxy versions 3.2.3 through 3.3.4 are affected by a vulnerability in how the RemoteAddr field processes IPv6 addresses when setting forwarded headers. An unauthenticated attacker can exploit this flaw by initiating a request over an IPv6 connection. Due to improper parsing of the source address, the application can be forced to accept an arbitrary value provided in the X-Forwarded-For header as the legitimate source IP. This vulnerability is significant for organizations that rely on IP-based allowlisting or access control lists (ACLs) within the Zoraxy reverse proxy or the services it protects. By spoofing a trusted internal or management IP, an attacker may gain unauthorized access to restricted application endpoints or bypass secondary authentication measures that rely on network location.

Impact

The vulnerability allows for the bypass of IP-based security controls, potentially granting unauthenticated access to sensitive administrative interfaces or internal services protected by the reverse proxy. Attackers can leverage this to gain unauthorized entry to backend systems that trust the X-Forwarded-For header provided by the proxy.

Recommendation

Update Zoraxy to a version newer than 3.3.4 to remediate CVE-2026-100390. If immediate patching is not feasible, restrict external IPv6 access to the Zoraxy management interfaces or application endpoints that utilize IP-based filtering.

Mitigations

Upgrade Zoraxy to a version newer than 3.3.4

immediate IT Operations

CVE-2026-100390