Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
Anubis: Policy bypass via client controlled X-Original-URI header
CVE-2026-62314
Description
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching r.URL.Path, allowing an HTTP client to match default data/common/keep-internet-working.yaml ALLOW rules such as ^/\.well-known/.*$ and bypass the Anubis challenge. This issue is fixed in version 1.26.0-pre1.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/TecharoHQ/anubis/commit/276b537776b281b1c4e01421435bc03ade3d8fc4mitrex_refsource_MISC
- github.com/TecharoHQ/anubis/pull/1630mitrex_refsource_MISC
- github.com/TecharoHQ/anubis/releases/tag/v1.26.0-pre1mitrex_refsource_MISC
- github.com/TecharoHQ/anubis/security/advisories/GHSA-6wcg-mqvh-fcvgmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.