๐Ÿ” CVE Alert

CVE-2026-103592

MEDIUM 6.5

simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.

CWE CWE-348
Vendor pecee
Product simple-router
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for pecee simple-router

Be the first to know when new medium vulnerabilities affecting pecee simple-router are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

pecee / simple-router
0 โ‰ค 5.4.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/skipperbent/simple-php-router/issues/727 github.com: https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php github.com: https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php github.com: https://github.com/skipperbent/simple-php-router vulncheck.com: https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers

Credits

Ikram-4