CVE-2026-108736

Published: Ott 11, 2026 Last Modified: Ott 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW 3,7
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none

Description

AI Translation Available

Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.

348

Use of Less Trusted Source

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/alexjustesen/speedtest-tracker
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://hackmd.io/@haind03/speedtest-tracker-trust-proxies-allowlist-bypass
https://www.vulncheck.com/advisories/speedtest-tracker-through-1.15.0-ip-allowl…