Description
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability allows an attacker to inject or forge client‑IP headers that the GeoIP extension trusts, enabling spoofing of the originating IP address. Because the extension uses these forwarded headers for GeoIP lookups and subsequent access‑control decisions, a spoofed IP can bypass geo‑blocking rules or other geolocation‑based restrictions. This grants an attacker the ability to compromise the integrity of location‑based checks and potentially gain access to restricted content or services. The weakness is identified as Authentication Spoofing (CWE‑290).

Affected Systems

The affected product is the GeoIP extension for Joomla maintained by regularlabs.com. No specific version range is provided in the current data; administrators should review installed extension versions against the vendor’s release notes for known fixes.

Risk and Exploitability

The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this analysis. The CVSS score of 6.5 reflects a medium severity vulnerability. Although not listed in the CISA KEV catalog, the ability to spoof client‑IP headers and bypass geo‑blocking rules can have significant operational effects. Based on the description, the likely attack vector is inferred to involve the attacker crafting custom forwarded‑IP headers to a server running the vulnerable GeoIP extension, typically achieved by controlling HTTP requests to the Joomla site.

Generated by OpenCVE AI on August 2, 2026 at 17:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the GeoIP extension to the latest vendor version where trusts of forwarded‑client IP headers have been removed or fixed.
  • Reconfigure the extension to ignore or reject forwarded‑client IP headers and enforce use of the true remote IP address only for geo‑lookup operations.
  • Apply Joomla core updates and disable any unnecessary or untrusted extensions to reduce the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 17:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com geoip Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com geoip Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass. Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
Title Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension
Weaknesses CWE-290
References

Subscriptions

Regularlabs.com Geoip Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:32:38.703Z

Reserved: 2026-07-20T18:46:40.119Z

Link: CVE-2026-64875

cve-icon Vulnrichment

Updated: 2026-07-27T13:26:21.220Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:52.400

Modified: 2026-07-27T14:16:59.970

Link: CVE-2026-64875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:15:05Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing