CVE-2026-103592
simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
| CWE | CWE-348 |
| Vendor | pecee |
| Product | simple-router |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for pecee simple-router
Be the first to know when new medium vulnerabilities affecting pecee simple-router are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
pecee / simple-router
0 โค 5.4.1.7
References
github.com: https://github.com/skipperbent/simple-php-router/issues/727 github.com: https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php github.com: https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php github.com: https://github.com/skipperbent/simple-php-router vulncheck.com: https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers
Credits
Ikram-4