CVE-2026-75514

⚪ Do wiadomości

BunkerWeb pozwala na obejście czarnej listy i wyzwania antybota przez zdalnego atakującego.

CVSS
5.9
EPSS
0.5%
Exploit
none
Vendor
Opis źródłowy (NVD)

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GREYLIST_RDNS, and ANTIBOT_IGNORE_RDNS without using get_ips to confirm that the hostname resolves to the client address. An unauthenticated remote attacker who controls a PTR record can spoof a trusted suffix to bypass rDNS-based blacklisting, gain greylist treatment, or skip an antibot challenge. This issue is fixed in version 1.6.13.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.5%
Opublikowano (NVD)2026-08-20 19:17:03 UTC
Ostatnia modyfikacja (NVD)2026-09-18 20:09:01 UTC
Referencje