{"id":"GHSA-6wcg-mqvh-fcvg","summary":"Anubis: Policy bypass via client controlled X-Original-URI header","details":"Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved.\nAffected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015)\n\nThe root cause is in `lib/policy/checker.go`, `PathChecker.Check()`:\n```go\nfunc (pc *PathChecker) Check(r *http.Request) (bool, error) {\n    originalUrl := r.Header.Get(\"X-Original-URI\")\n    if originalUrl != \"\" {\n        if pc.regexp.MatchString(originalUrl) {\n            return true, nil\n        }\n    }\n    if pc.regexp.MatchString(r.URL.Path) {\n        return true, nil\n    }\n    return false, nil\n}\n```\n\nThe header value comes directly from the client request. The middleware chain never strips it. In reverse proxy mode an attacker fully controls it.\nThe default policy imports `data/common/keep-internet-working.yaml`, which contains path-only ALLOW rules with no other conditions:\n\n```yaml\n- name: well-known\n  path_regex: ^/\\.well-known/.*$\n  action: ALLOW\n```\n\nWhen `X-Original-URI` matches one of those regexes, the rule fires as ALLOW and the request is forwarded upstream without any challenge or JWT check.\n\n\n# Proof of concept\n\nNormal request, gets challenged:\n```\ncurl -s https://anubis.techaro.lol/ | grep -o \"\u003ctitle\u003e.*\u003c/title\u003e\"\n```\n\nBypass, gets upstream content:\n```\ncurl -s -H \"X-Original-URI: /.well-known/x\" https://anubis.techaro.lol/ | grep -o \"\u003ctitle\u003e.*\u003c/title\u003e\"\n```\n\nThe first command returns the Anubis challenge page title. The second returns the real site title directly, with no cookie set and no challenge issued. Verified live against anubis.techaro.lol.\n\n# Suggested fix\nThe fix should probably be to strip the header from incoming client requests in the middleware chain before policy evaluation. In `auth_request` mode the header is set by the proxy after Anubis processes the middleware, so stripping it at ingress does not break that deployment mode.","aliases":["CVE-2026-62314"],"modified":"2026-10-02T18:30:39.766334532Z","published":"2026-10-02T18:22:08Z","database_specific":{"cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-02T18:22:08Z","nvd_published_at":"2026-07-15T22:17:38Z"},"references":[{"type":"WEB","url":"https://github.com/TecharoHQ/anubis/security/advisories/GHSA-6wcg-mqvh-fcvg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62314"},{"type":"WEB","url":"https://github.com/TecharoHQ/anubis/pull/1630"},{"type":"WEB","url":"https://github.com/TecharoHQ/anubis/commit/276b537776b281b1c4e01421435bc03ade3d8fc4"},{"type":"PACKAGE","url":"https://github.com/TecharoHQ/anubis"},{"type":"WEB","url":"https://github.com/TecharoHQ/anubis/releases/tag/v1.26.0-pre1"}],"affected":[{"package":{"name":"github.com/TecharoHQ/anubis","ecosystem":"Go","purl":"pkg:golang/github.com/TecharoHQ/anubis"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.22.0"},{"fixed":"1.26.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6wcg-mqvh-fcvg/GHSA-6wcg-mqvh-fcvg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"}]}