MEDIUM
alexjustesen
CVE published 2026-10-11
CVE-2026-108736
Speedtest Tracker through 1.15.0 contains an IP allowlist bypass vulnerability that allows unauthenticated remote attackers to evade ALLOWED_IPS and Prometheus allowlists by spoofing X-Forwarded-For headers. This vulnerability affects Speedtest Tracker instances, particularly those with publicly accessible web and API endpoints. Defenders should assess exposure and verify the effectiveness of current allo [truncated]