Project machine name: 
restrict_route_by_ip
Date: 
2026-October-07
Vulnerability: 
Access bypass
Affected versions: 
<1.3.1 || >=2.0.0 <2.0.1
CVE IDs: 
CVE-2026-107255
Description: 

This module enables you to restrict access to routes by IP address.

The module doesn't reliably restrict a subset of dynamic routes, leading to an access bypass vulnerability. The impact depends on how a site uses this module and whether it has any routes that are dynamic.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: