---
id: CVE-2026-103592
title: >-
  simple-php-router through 5.4.1.7 contains an IP restriction bypass
  vulnerability in the IpRestrictAccess middleware that allows remote
  unauthenticated attackers to bypass IP whitelist and blacklist protections
summary: >-
  simple-php-router through 5.4.1.7 contains an IP restriction bypass
  vulnerability in the IpRestrictAccess middleware that allows remote
  unauthenticated attackers to bypass IP whitelist and blacklist protections.
  Attackers can spoof X-For…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-348
vendor: pecee
product: simple-router
affected:
  - simple-router <= 5.4.1.7
published: '2026-09-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T02:20:29.877'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103592'
references:
  - url: 'https://github.com/skipperbent/simple-php-router'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Middleware/IpRestrictAccess.php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/skipperbent/simple-php-router/blob/5.4.1.7/src/Pecee/Http/Request.php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/skipperbent/simple-php-router/issues/727'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/simple-php-router-through-5.4.1.7-ip-restriction-bypass-via-forwarding-headers
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T23:29:32.580Z'
---

## Overview

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
