CVE-2026-108736
Speedtest Tracker through 1.15.0 IP Allowlist Bypass via X-Forwarded-For Spoofing
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
| CWE | CWE-348 |
| Vendor | alexjustesen |
| Product | speedtest-tracker |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for alexjustesen speedtest-tracker
Be the first to know when new low vulnerabilities affecting alexjustesen speedtest-tracker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
alexjustesen / speedtest-tracker
0 โค 1.15.0
References
hackmd.io: https://hackmd.io/@haind03/speedtest-tracker-trust-proxies-allowlist-bypass github.com: https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/bootstrap/app.php#L23-L41 github.com: https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/app/Http/Middleware/AllowedIpAddressesMiddleware.php#L16-L27 github.com: https://github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/app/Http/Middleware/PrometheusAllowedIpMiddleware.php#L22-L42 github.com: https://github.com/alexjustesen/speedtest-tracker vulncheck.com: https://www.vulncheck.com/advisories/speedtest-tracker-through-1.15.0-ip-allowlist-bypass-via-x-forwarded-for-spoofing
Credits
HaiND from the Post and Telecommunication Institute of Technology