Impact
Speedtest Tracker versions up to 1.15.0 contain an IP allowlist bypass that allows any unauthenticated client to supply a spoofed X‑Forwarded‑For header. The application, which trusts all proxies by default, interprets the header as the client’s real IP and checks it against the ALLOWED_IPS and Prometheus allowlists. Because the supplied IP can match an allowlisted address, attackers can access protected web and API endpoints and read the /prometheus metrics endpoint.
Affected Systems
The vulnerable product is Speedtest Tracker from the vendor alexjustesen. All releases with a version of 1.15.0 or earlier are affected, as the issue arises from code present in bootstrap/app.php that trusts every peer as a proxy. Later releases that adjust the proxy trust configuration or alter the allowlist logic may no longer be impacted, but the CVE specifically references the 1.15.0 version.
Risk and Exploitability
The flaw carries a CVSS score of 6.3, indicating moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness remotely by sending an HTTP request with a crafted X‑Forwarded‑For header from any network that reaches the application. No authentication or additional privileges are required, and the path to bypass the allowlist is straightforward once the header is accepted. The resulting unauthorized read of protected endpoints and Prometheus metrics could support reconnaissance or other attacks.
OpenCVE Enrichment