<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:zoraxy:zoraxy:3.3.4:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3azoraxyzoraxy3.3.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 22:55:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3azoraxyzoraxy3.3.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy</title><link>https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/</link><pubDate>Fri, 25 Sep 2026 22:55:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/</guid><description>Zoraxy versions 3.2.3 through 3.3.4 contain a vulnerability in IPv6 address parsing that allows unauthenticated attackers to spoof the X-Forwarded-For header and bypass IP-based access controls.</description><content:encoded><![CDATA[<p>Zoraxy versions 3.2.3 through 3.3.4 are affected by a vulnerability in how the RemoteAddr field processes IPv6 addresses when setting forwarded headers. An unauthenticated attacker can exploit this flaw by initiating a request over an IPv6 connection. Due to improper parsing of the source address, the application can be forced to accept an arbitrary value provided in the X-Forwarded-For header as the legitimate source IP. This vulnerability is significant for organizations that rely on IP-based allowlisting or access control lists (ACLs) within the Zoraxy reverse proxy or the services it protects. By spoofing a trusted internal or management IP, an attacker may gain unauthorized access to restricted application endpoints or bypass secondary authentication measures that rely on network location.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for the bypass of IP-based security controls, potentially granting unauthenticated access to sensitive administrative interfaces or internal services protected by the reverse proxy. Attackers can leverage this to gain unauthorized entry to backend systems that trust the X-Forwarded-For header provided by the proxy.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update Zoraxy to a version newer than 3.3.4 to remediate CVE-2026-100390. If immediate patching is not feasible, restrict external IPv6 access to the Zoraxy management interfaces or application endpoints that utilize IP-based filtering.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>webserver</category><category>network-security</category></item></channel></rss>