MEDIUM 5.8 GitHub
CVE-2026-62314
Anubis: Policy bypass via client controlled X-Original-URI header
Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved.
Affected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015)
The root cause is in `lib/policy/checker.go`, `PathChecker.Check()`:
```go
func (pc *PathChecker) Check(r *http.Request) (bool, error) {
originalUrl := r.Header.Get("X-Original-URI")
if originalUrl != "" {
if pc.regexp.MatchString(originalUrl) {
Affected Products
- go/github.com/TecharoHQ/anubis >= 1.22.0, < 1.26.0
References
- https://github.com/advisories/GHSA-6wcg-mqvh-fcvg
- https://github.com/TecharoHQ/anubis/security/advisories/GHSA-6wcg-mqvh-fcvg
- https://nvd.nist.gov/vuln/detail/CVE-2026-62314
- https://github.com/TecharoHQ/anubis/pull/1630
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-02 via GitHub. Affected: go/github.com/TecharoHQ/anubis >= 1.22.0, < 1.26.0.
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.