CVE-2026-100390High· 7.4▾ TwilightZoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84465High· 7.1Zammad is a web based open source helpdesk/customer support system
CVE-2026-44118High· 7.8OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header
CVE-2026-48567Critical· 10.0Azure HorizonDB Elevation of Privilege Vulnerability
CVE-2026-94416Medium· 6.8An authorization bypass was found in the Ansible Automation Platform (AAP) gateway
CVE-2026-94457Medium· 4.8Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.
CVE-2026-95523Medium· 6.5Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.