CVE-2026-103592 simple-php-router through 5.4.1.7 contains an IP… — CVE Notify — TG.ME

🚨 CVE-2026-103592
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.

🎖@cveNotify
GitHub
GitHub - skipperbent/simple-php-router: Simple, fast and yet powerful PHP router that is easy to get integrated and in any project.…
Simple, fast and yet powerful PHP router that is easy to get integrated and in any project. Heavily inspired by the way Laravel handles routing, with both simplicity and expand-ability in mind. - s...
September 30, 2026 35
CVE-2026-103592 simple-php-router through 5.4.1.7 contains an IP… — CVE Notify — TG.ME