Description
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
Published: 2026-10-11
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Bypass of IP allowlist, granting unauthenticated access to protected endpoints and metrics.
Action: Apply Patch
AI Analysis

Impact

Speedtest Tracker versions up to 1.15.0 contain an IP allowlist bypass that allows any unauthenticated client to supply a spoofed X‑Forwarded‑For header. The application, which trusts all proxies by default, interprets the header as the client’s real IP and checks it against the ALLOWED_IPS and Prometheus allowlists. Because the supplied IP can match an allowlisted address, attackers can access protected web and API endpoints and read the /prometheus metrics endpoint.

Affected Systems

The vulnerable product is Speedtest Tracker from the vendor alexjustesen. All releases with a version of 1.15.0 or earlier are affected, as the issue arises from code present in bootstrap/app.php that trusts every peer as a proxy. Later releases that adjust the proxy trust configuration or alter the allowlist logic may no longer be impacted, but the CVE specifically references the 1.15.0 version.

Risk and Exploitability

The flaw carries a CVSS score of 6.3, indicating moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness remotely by sending an HTTP request with a crafted X‑Forwarded‑For header from any network that reaches the application. No authentication or additional privileges are required, and the path to bypass the allowlist is straightforward once the header is accepted. The resulting unauthorized read of protected endpoints and Prometheus metrics could support reconnaissance or other attacks.

Generated by OpenCVE AI on October 11, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Speedtest Tracker to a release where the proxy trust logic has been changed so that X‑Forwarded‑For headers from untrusted proxies are no longer accepted.
  • If an upgrade is not possible immediately, modify bootstrap/app.php to replace the line that trusts every peer with a whitelist of known internal proxy IPs or remove that trust entirely, ensuring that only trusted proxies can supply the header.
  • Secure the /prometheus metrics endpoint by requiring authentication, moving it behind a reverse‑proxy firewall, or otherwise limiting access to the metric data.

Generated by OpenCVE AI on October 11, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
Title Speedtest Tracker through 1.15.0 IP Allowlist Bypass via X-Forwarded-For Spoofing
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:42.324Z

Reserved: 2026-10-11T01:52:49.073Z

Link: CVE-2026-108736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:17.913

Modified: 2026-10-11T13:17:17.913

Link: CVE-2026-108736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:15:18Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source