CVE-2026-100390: Tobychui Zoraxy
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Affected products
- Tobychui Zoraxy: from 3.2.3, up to and including 3.3.4
Published 2026-09-25. Last modified 2026-09-30.