What is CVE-2026-64875?
This vulnerability exists in the Regular Labs GeoIP extension for Joomla. It trusts spoofable 'forwarded' client-IP headers, allowing attackers to bypass GeoIP-based rules via IP spoofing. Immediate update to the latest version of the extension is recommended.
Azərbaycanca: Bu zəiflik Regular Labs tərəfindən hazırlanmış Joomla GeoIP genişlənməsində aşkarlanıb. Təcavüzkar saxtalaşdırıla bilən 'forwarded' IP başlıqları vasitəsilə IP spoofing həyata keçirə, GeoIP əsaslı qaydaları keçə bilər. Ən qısa zamanda genişlənməni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What can an attacker achieve by exploiting CVE-2026-64875?
The attacker can perform IP spoofing through spoofable 'forwarded' client-IP headers and bypass GeoIP-based rules.
How can one protect against CVE-2026-64875?
It is recommended to update the Regular Labs GeoIP extension to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.