Description
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote unauthorized access by bypassing IP restrictions
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the IpRestrictAccess middleware of simple‑php‑router allows an attacker to forge HTTP headers such as X‑Forwarded‑For, CF‑Connecting‑IP, or Client‑IP. By spoofing these values, an unauthenticated remote user can impersonate a whitelisted address or bypass a blacklist and gain access to routes that are intended to be IP‑restricted. The flaw falls under CWE‑348, which describes IP address spoofing attacks. As a result, application logic that relies on IP checks can be subverted, potentially exposing sensitive functionality or data.

Affected Systems

The build of simple‑php‑router through version 5.4.1.7 is affected. This affects deployments that mount Pecee’s simple‑router package without updating beyond the listed version. No other vendor or product has been identified as impacted within this CVE entry.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high risk level. Because the EPSS score is unavailable, the exact likelihood of exploitation remains unclear, but the absence of a KEV listing suggests no confirmed widespread exploitation yet. The likely attack vector is remote HTTP requests to an application that uses the IpRestrictAccess middleware; it requires that the server does not restrict or sanitize forwarded‑for style headers. In practice, any client that can send arbitrary HTTP requests to the router can attempt to spoof headers and test whether the middleware is enforcing real source IPs. The vulnerability’s impact is limited to the authentication or restriction model in place, but compromising a protected route could allow further exploitation such as privilege escalation or data disclosure.

Generated by OpenCVE AI on October 1, 2026 at 00:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade simple‑php‑router to a version that includes the IpRestrictAccess fix.
  • Configure the middleware or application environment to ignore or explicitly validate X‑Forwarded‑For, CF‑Connecting‑IP, and Client‑IP headers, or to trust such headers only when the request originates from a trusted reverse proxy.
  • Ensure that the application’s IP‑whitelisting logic verifies the originating IP from the server’s connection socket rather than relying on forwarded headers alone.

Generated by OpenCVE AI on October 1, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
Title simple-php-router through 5.4.1.7 IP restriction bypass via forwarding headers
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T23:02:36.416Z

Reserved: 2026-09-30T22:32:08.870Z

Link: CVE-2026-103592

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T23:16:58.963

Modified: 2026-09-30T23:16:58.963

Link: CVE-2026-103592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T00:30:06Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source