External risk intelligence

Zoraxy IPv6 Address Parsing Vulnerability Allows Source IP Spoofing

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-100390

Zoraxy is a web proxy and reverse proxy software. By nature of its product role, it is commonly deployed at the network edge to handle incoming web traffic and forward requests, making it a likely candidate for public internet exposure.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in Zoraxy software that could allow attackers to spoof their origin by manipulating forwarded headers over IPv6. This could potentially bypass access controls based on IP addresses. The main concern is confirming if this technology is in use and exposed to potential threats.

  • Attackers can impersonate user IPs.
  • Critical for any systems using this software.
  • Verify software usage and exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this by connecting to the Zoraxy service over IPv6. By sending specially crafted requests with forged `X-Forwarded-For` headers, the attacker can trick Zoraxy into believing the request originates from an IP address that is authorized. This allows the attacker to bypass IP-based access controls and potentially reach other sensitive functionalities or data within the application.

  • Entry condition: Network access over IPv6.
  • Trigger point: Sending custom IPv6 `X-Forwarded-For` headers.
  • Resulting risk: Bypass IP access controls.

Live Threat

Current exploitation, exposure, and threat context

When Zoraxy improperly parses IPv6 addresses in the RemoteAddr field of forwarded headers, unauthenticated attackers can spoof their source IP address. This occurs when the software is configured to use IPv6 and attackers can send specially crafted requests to bypass IP-based access controls that rely on the accuracy of the forwarded client IP.

  • Network access controls could be bypassed.
  • Attackers spoof IP addresses via forwarded headers.
  • Unauthorized access to services may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world mitigation likely involves infrastructure or platform teams responsible for the Zoraxy proxy deployment. The initial step is to identify all instances of Zoraxy, confirm their exposure to IPv6 networks and any business-critical functions they support, and then assign an owner for remediation planning.

  • Identify affected Zoraxy instances.
  • Verify IPv6 reachability and business impact.
  • Plan and coordinate remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Zoraxy software?

Zoraxy is an open-source web proxy and reverse proxy application. It is primarily used to manage, route, and secure incoming web traffic for servers, acting as a gateway that sits between external users and internal web services to handle requests and load balancing.

How does CVE-2026-100390 work?

This vulnerability is classified as CWE-290, which involves Authentication Bypass by Spoofing. In affected Zoraxy versions, the software fails to correctly parse IPv6 addresses when processing forwarded headers. This weakness allows an attacker to inject arbitrary data into the X-Forwarded-For header, tricking the proxy into trusting a false, authorized origin IP.

Do I need IPv6 to trigger this bug?

Yes, the vulnerability is triggered by requests arriving over an IPv6 connection. The flaw specifically exists in the logic handling the RemoteAddr field for IPv6 traffic. Connections made exclusively over IPv4 do not encounter this specific parsing error, meaning the exploit path requires an attacker to route their traffic through the IPv6 protocol.

Is my Zoraxy instance at risk?

According to Halo Surface Signal, Zoraxy is often deployed at the network edge to handle public web traffic, making it a likely candidate for internet exposure. If your proxy handles incoming requests from the public internet and you rely on IP-based allowlists for security, your environment is at a higher risk of being targeted by this spoofing technique.

What is the first step to address this?

Begin by auditing your infrastructure to locate all active Zoraxy instances. Once identified, confirm if these proxies are configured to process IPv6 traffic and determine if they use IP-based access controls for security. Establish ownership of these assets to coordinate a planned update or mitigation strategy as prescribed by the project maintainers.

References