MEDIUM 5.8 GitHub

CVE-2026-62314

Anubis: Policy bypass via client controlled X-Original-URI header

Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved. Affected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015) The root cause is in `lib/policy/checker.go`, `PathChecker.Check()`: ```go func (pc *PathChecker) Check(r *http.Request) (bool, error) { originalUrl := r.Header.Get("X-Original-URI") if originalUrl != "" { if pc.regexp.MatchString(originalUrl) {

Affected Products

References

Published: 2026-10-02 · Source: GitHub · Feed updated: 2026-10-02
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-02 via GitHub. Affected: go/github.com/TecharoHQ/anubis >= 1.22.0, < 1.26.0.
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.