PatchSiren

alexjustesen CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM alexjustesen CVE published 2026-10-11

CVE-2026-108736

Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. This vulnerability affects Speedtest Tracker instances, particularly those with publicly accessible web and API endpoints. Defenders should assess exposure and verify the effectiveness of current allo [truncated]