IP Allowlist Bypass in Speedtest Tracker by Alex Justesen
CVE-2026-108736
6.3MEDIUM
What is CVE-2026-108736?
The Speedtest Tracker application prior to version 1.15.0 contains a vulnerability that allows unauthenticated remote attackers to bypass the IP allowlist by spoofing X-Forwarded-For headers. This occurs because the application improperly trusts all peers as proxies, permitting attackers to manipulate the request and provide an address that is considered allowlisted. Consequently, this exploitation grants unauthorized access to sensitive /prometheus metrics and protected web and API endpoints, leading to potential data leaks and unauthorized operations.
Affected Version(s)
speedtest-tracker 0 <= 1.15.0
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
