Sceawere
Vulnerability Detail
CVE-2026-108736UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Speedtest Tracker IP Allowlist Bypass
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 4h ago
- Vendor
- alexjustesen
- Product
- speedtest-tracker
- Attack Type
- Use of Less Trusted Source
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. Because bootstrap/app.php trusts every peer as a proxy, attackers can supply an allowlisted address to read /prometheus metrics and reach protected web and API endpoints.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-11T13:17:17.913Z",
"pubdate": "2026-10-11T13:17:17.913Z",
"executiveSummary": "Speedtest Tracker versions up to and including 1.15.0 are affected by an IP allowlist bypass vulnerability categorized as an authentication and access control bypass. The issue stems from the improper configuration of trusted proxies within the application, specifically within bootstrap/app.php. By failing to validate the source of X-Forwarded-For headers, the application treats all incoming traffic as potentially originating from a trusted proxy.\nThis vulnerability allows unauthenticated remote attackers to spoof their source IP address, enabling them to bypass restrictions configured in ALLOWED_IPS and Prometheus allowlists. Successful exploitation grants attackers unauthorized access to sensitive endpoints, including Prometheus metrics and other protected web and API interfaces. The risk is significant as it effectively negates network-level access controls designed to protect internal or administrative functions from public exposure. No authentication is required to perform this attack, as the flaw resides at the perimeter of the application's request handling logic.\nThe potential impact includes information disclosure via metrics exposure and potential interaction with restricted API endpoints that rely on source IP validation for security.",
"technicalDetails": "The root cause of this vulnerability is a misconfiguration in the request handling architecture of Speedtest Tracker, specifically located in bootstrap/app.php. The application is configured to implicitly trust any peer acting as a proxy without implementing a strict validation mechanism for the source or integrity of forwarded request headers.\nIn web environments, headers such as X-Forwarded-For are used to identify the originating IP address of a client connecting to a web server through an HTTP proxy or a load balancer. If an application blindly trusts these headers without confirming the legitimacy of the preceding hop, an attacker can inject arbitrary IP addresses into the header. Because the application logic relies on these headers to verify if a request originates from an address defined in the ALLOWED_IPS configuration or the Prometheus allowlist, the forged header effectively tricks the application's security checks.\nThe attack flow proceeds as follows: 1. An attacker identifies the target Speedtest Tracker instance. 2. The attacker crafts an HTTP request targeting a restricted endpoint, such as /prometheus or other protected administrative/API routes. 3. The attacker adds or modifies the 'X-Forwarded-For' header in the HTTP request, setting the value to an IP address that is explicitly included in the application's allowlist configuration. 4. The application, specifically the logic processed via bootstrap/app.php, parses the forged header. 5. Due to the lack of trusted proxy verification, the application accepts the spoofed IP as the genuine remote address. 6. The internal authorization check compares the spoofed IP against the allowlist, confirms a match, and grants the attacker access to the restricted resource.\nThis bypass exposes the Prometheus metrics endpoint, which may leak sensitive environmental configuration, system performance data, or other infrastructure-related details. Furthermore, any API endpoint that uses IP-based ACLs for access control becomes vulnerable to unauthorized interaction. The vulnerability is present in all versions through 1.15.0. Exploitation requires no prior authentication and can be performed from any network path capable of reaching the web server. The behavior of the payload is strictly header manipulation, requiring no complex binary exploitation or memory corruption, making it a highly accessible vector for remote attackers seeking to circumvent perimeter security."
}