
🟠 Anubis, Policy Bypass, #CVE-2026-62314 (Medium) -DC-Oct2026-2703 https://dailycve.com/anubis-policy-bypass-cve-2026-62314-medium-dc-oct2026-2703/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching r.URL.Path, allowing an HTTP client to match default data/common/keep-internet-working.yaml ALLOW rules such as ^/\.well-known/.*$ and bypass the Anubis challenge. This issue is fixed in version 1.26.0-pre1.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🟠 Anubis, Policy Bypass, #CVE-2026-62314 (Medium) -DC-Oct2026-2703 https://dailycve.com/anubis-policy-bypass-cve-2026-62314-medium-dc-oct2026-2703/