PT-2026-60328 · Anubis · Anubis

CVE-2026-62314

·

Published

2026-07-15

·

Updated

2026-08-12

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Anubis versions 1.22.0 through 1.26.0-pre1
Description Anubis is a Web AI Firewall Utility designed to protect upstream resources from scraper bots by challenging user connections. A flaw exists in the PathChecker.Check() function within lib/policy/checker.go where the utility trusts the client-controlled X-Original-URI header before matching r.URL.Path. This allows an HTTP client to match default ALLOW rules, such as ^/.well-known/.*$, and bypass the Anubis challenge.
Recommendations Update Anubis to version 1.26.0-pre1.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62314
GHSA-6WCG-MQVH-FCVG

Affected Products

Anubis