VYPR

speedtest-tracker

by Speedtest Tracker

CVEs (1)

  • CVE-2026-108736LowOct 11, 2026
    risk 0.17cvss 3.7epss —

    Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can…