{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/zoraxy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zoraxy:zoraxy:3.2.3:*:*:*:*:*:*:*","cpe:2.3:a:zoraxy:zoraxy:3.3.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-100390"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Zoraxy (3.2.3 - 3.3.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","webserver","network-security"],"_cs_type":"advisory","_cs_vendors":["Zoraxy"],"content_html":"\u003cp\u003eZoraxy versions 3.2.3 through 3.3.4 are affected by a vulnerability in how the RemoteAddr field processes IPv6 addresses when setting forwarded headers. An unauthenticated attacker can exploit this flaw by initiating a request over an IPv6 connection. Due to improper parsing of the source address, the application can be forced to accept an arbitrary value provided in the X-Forwarded-For header as the legitimate source IP. This vulnerability is significant for organizations that rely on IP-based allowlisting or access control lists (ACLs) within the Zoraxy reverse proxy or the services it protects. By spoofing a trusted internal or management IP, an attacker may gain unauthorized access to restricted application endpoints or bypass secondary authentication measures that rely on network location.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for the bypass of IP-based security controls, potentially granting unauthenticated access to sensitive administrative interfaces or internal services protected by the reverse proxy. Attackers can leverage this to gain unauthorized entry to backend systems that trust the X-Forwarded-For header provided by the proxy.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate Zoraxy to a version newer than 3.3.4 to remediate CVE-2026-100390. If immediate patching is not feasible, restrict external IPv6 access to the Zoraxy management interfaces or application endpoints that utilize IP-based filtering.\u003c/p\u003e\n","date_modified":"2026-09-25T22:55:37Z","date_published":"2026-09-25T22:55:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/","summary":"Zoraxy versions 3.2.3 through 3.3.4 contain a vulnerability in IPv6 address parsing that allows unauthenticated attackers to spoof the X-Forwarded-For header and bypass IP-based access controls.","title":"CVE-2026-100390 - IP Spoofing Vulnerability in Zoraxy","url":"https://feed.craftedsignal.io/briefs/2026-09-zoraxy-ipv6-spoofing/"}],"language":"en","title":"CraftedSignal Threat Feed - Zoraxy","version":"https://jsonfeed.org/version/1.1"}