Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75514— BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot

Quick assessment

Affected
bunkerity bunkerweb
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

BunkerWeb 是一款开源的下一代 Web 应用防火墙。在 1.6.13 版本之前, 、 以及 中的黑名单、灰名单和反机器人模块,在处理环境变量 、 和 中的 PTR 后缀匹配时存在信任缺陷:它们未通过 函数确认主机名确实解析到客户端的实际 IP 地址。这使得未认证的远程攻击者,若能控制某个 PTR 记录,即可伪造受信任的后缀,从而绕过基于反向 DNS(rDNS)的黑名单机制、使请求进入灰名单处理流程,或逃避反机器人挑战。该问题已在 1.6.13 版本中修复。

CVSS 5.9 · Medium EPSS 0.46% · P38

Affected Version Matrix 1

VendorProduct Version RangeStatus
bunkerity bunkerweb < 1.6.13 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75514

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
Source: CVE Program / CVE List V5
Vulnerability Description
BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GREYLIST_RDNS, and ANTIBOT_IGNORE_RDNS without using get_ips to confirm that the hostname resolves to the client address. An unauthenticated remote attacker who controls a PTR record can spoof a trusted suffix to bypass rDNS-based blacklisting, gain greylist treatment, or skip an antibot challenge. This issue is fixed in version 1.6.13.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不恰当地信任反向DNS
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bunkerity bunkerweb < 1.6.13 -

II. Public POCs for CVE-2026-75514

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75514

登录查看更多情报信息。

Patches & Fixes for CVE-2026-75514 (1)

Vendor Advisories for CVE-2026-75514 (1)

Vendor Pages for CVE-2026-75514 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75514

No comments yet


Leave a comment