CVE-2026-108736
Received Received - Intake

Speedtest Tracker IP Allowlist Bypass via X-Forwarded-For Spoofing

Vulnerability report for CVE-2026-108736, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
alexjustesen speedtest-tracker 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-348 The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Speedtest Tracker through version 1.15.0 has an IP allowlist bypass flaw. Unauthenticated remote attackers can evade IP restrictions by spoofing the X-Forwarded-For header. The application trusts all proxies, allowing attackers to supply an allowlisted IP address to access protected endpoints and metrics.

Detection Guidance

To detect this vulnerability, inspect network traffic for requests containing spoofed X-Forwarded-For headers. Check if the application logs show access to /prometheus metrics or protected endpoints from untrusted sources. Verify if the ALLOWED_IPS or Prometheus allowlists are being bypassed by testing with crafted headers.

Impact Analysis

Attackers could bypass IP-based access controls to access sensitive data, read /prometheus metrics, or interact with protected web and API endpoints without authentication. This could lead to unauthorized data exposure or system manipulation.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles or HIPAA's access controls. Organizations may face compliance violations, fines, or reputational damage due to insufficient IP-based access restrictions.

Mitigation Strategies

Immediately update Speedtest Tracker to the latest version beyond 1.15.0. Configure the application to reject requests with X-Forwarded-For headers unless from trusted proxies. Restrict access to /prometheus metrics and protected endpoints to authorized IPs only. Review and tighten proxy configurations to prevent header spoofing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108736. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart