CVE-2026-108736
MEDIUM
6,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
348
Use of Less Trusted Source
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://github.com/alexjustesen/speedtest-tracker
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c3…
https://hackmd.io/@haind03/speedtest-tracker-trust-proxies-allowlist-bypass
https://www.vulncheck.com/advisories/speedtest-tracker-through-1.15.0-ip-allowl…