CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103592

MEDIUMCVSS 6.5NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersona

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103592 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103592

MEDIUMCVSS 6.5NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersona

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]