No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls. | |
| Title | Zoraxy 3.2.3 through 3.3.4 Client IP Spoofing via X-Forwarded-For IPv6 | |
| First Time appeared |
Zoraxy
Zoraxy zoraxy |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:zoraxy:zoraxy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zoraxy
Zoraxy zoraxy |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T20:42:50.268Z
Reserved: 2026-09-25T19:47:54.241Z
Link: CVE-2026-100390
Updated: 2026-09-25T20:42:46.303Z
Status : Received
Published: 2026-09-25T21:17:22.637
Modified: 2026-09-25T21:17:22.637
Link: CVE-2026-100390
No data.
OpenCVE Enrichment
No data.
-
CWE-290
Authentication Bypass by Spoofing