Listen to this Post
CVE-2026-62314 is a policy bypass vulnerability in Anubis, a Web AI Firewall Utility designed to challenge users’ connections to protect upstream resources from scraper bots. The vulnerability exists in the `PathChecker.Check()` function within lib/policy/checker.go, which improperly trusts the client-controlled `X-Original-URI` header before evaluating the actual request path. This flaw allows any HTTP client to bypass Anubis’s bot protection on the default configuration by simply adding a single request header, without solving any challenge. The affected versions are v1.22.0 through v1.25.0, with the vulnerability introduced in commit d1d631a (PR 1015). The root cause is that the `X-Original-URI` header value comes directly from the client request, and the middleware chain never strips it. In reverse proxy mode, an attacker fully controls this header. The default policy imports data/common/keep-internet-working.yaml, which contains path-only ALLOW rules with no other conditions, such as allowing ^/\.well-known/.$. When the `X-Original-URI` header matches one of these regexes, the rule fires as ALLOW and the request is forwarded upstream without any challenge or JWT check. This represents a classic case of insecure input handling where user-supplied data is trusted without proper validation. The vulnerability aligns with CWE-20 (Improper Input Validation) and CWE-284 (Improper Access Control). The CVSS 3.1 score is 5.8, rated Medium, with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N. The issue is fixed in version 1.26.0-pre1, where client-controlled headers are no longer trusted for security decision-making. Security recommendations include implementing strict header validation policies and ensuring client-supplied values are never directly used in access control decisions without additional verification.
DailyCVE Form:
Platform: Anubis
Version: 1.22.0-1.25.0
Vulnerability: Policy Bypass
Severity: Medium
date: 2026-07-15
Prediction: 2026-07-16
What Undercode Say:
Normal request, gets challenged: curl -s https://anubis.techaro.lol/ | grep -o "<>.</>" Bypass, gets upstream content: curl -s -H "X-Original-URI: /.well-known/x" https://anubis.techaro.lol/ | grep -o "<>.</>"
func (pc PathChecker) Check(r http.Request) (bool, error) {
originalUrl := r.Header.Get("X-Original-URI")
if originalUrl != "" {
if pc.regexp.MatchString(originalUrl) {
return true, nil
}
}
if pc.regexp.MatchString(r.URL.Path) {
return true, nil
}
return false, nil
}
- name: well-known path_regex: ^/.well-known/.$ action: ALLOW
How Exploit: (Educational Purposes!)
1. Identify an Anubis-protected endpoint.
- Craft an HTTP request with the header
X-Original-URI: /.well-known/x. - Send the request; the policy checker matches the header against the ALLOW regex, bypassing the challenge and returning the upstream content.
Protection: from this CVE
Strip the `X-Original-URI` header from incoming client requests in the middleware chain before policy evaluation. Upgrade to version 1.26.0-pre1 or later.
Impact:
Attackers can bypass bot protection, leading to data scraping, service abuse, and resource exhaustion. The vulnerability compromises the fundamental security posture of Anubis by enabling unrestricted access to upstream resources.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

