CVE-2026-103592 Details
Description
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
A vulnerability exists in simple-php-router versions through 5.4.1.7, allowing remote unauthenticated attackers to bypass IP restrictions. The issue is located in the IpRestrictAccess middleware, where the getIp() method can be manipulated by spoofing the X-Forwarded-For, CF-Connecting-IP, or Client-IP headers. This exploitation can impersonate whitelisted IP addresses or evade blacklisted ones, granting access to routes that are otherwise protected by IP restrictions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/skipperbent/simple-php-router | [email protected] | Vendor |
| https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php | [email protected] | Source CodeVendor |
| https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php | [email protected] | Source CodeVendor |
| https://github.com/skipperbent/simple-php-router/issues/727 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pecee\SimpleRouter | <= 5.4.1.7 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion