Low severity3.7NVD Advisory· Published Oct 11, 2026
CVE-2026-108736
CVE-2026-108736
Description
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.15.0
<=1.15.0+ 1 more
- (no CPE)range: <=1.15.0
- (no CPE)
Patches
Vulnerability mechanics
References
5- github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/app/Http/Middleware/AllowedIpAddressesMiddleware.phpnvd
- github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/app/Http/Middleware/PrometheusAllowedIpMiddleware.phpnvd
- github.com/alexjustesen/speedtest-tracker/blob/fce6eb36181ed70b5b0763c391a50b806d7e3da7/bootstrap/app.phpnvd
- hackmd.io/@haind03/speedtest-tracker-trust-proxies-allowlist-bypassnvd
- www.vulncheck.com/advisories/speedtest-tracker-through-1.15.0-ip-allowlist-bypass-via-x-forwarded-for-spoofingnvd
News mentions
0No linked articles in our index yet.