CVE-2026-100390
7.4 HIGHpublic exploit availablePublished 2026-09-25 · Updated 2026-09-25
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-290
Public exploit & PoC references
All references
- https://github.com/tobychui/zoraxy
- https://github.com/tobychui/zoraxy/blob/v3.3.4/src/mod/auth/sso/forward/util.go#L127-L142
- https://github.com/tobychui/zoraxy/commit/56bb3e5abb83eae42a64203028d73a001d6096c4
- https://github.com/tobychui/zoraxy/pull/1264
- https://www.vulncheck.com/advisories/zoraxy-3.2.3-through-3.3.4-client-ip-spoofing-via-x-forwarded-for-ipv6
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-101280
- UNSCOREDCVE-2026-40854
- HIGHCVE-2026-55210PoC
- CRITICALCVE-2026-61682PoC
- CRITICALCVE-2026-62108
- MEDIUMCVE-2026-62987PoC
- MEDIUMCVE-2026-63329PoC
- UNSCOREDCVE-2026-84465PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.