Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91002— stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication

Quick assessment

Affected
stamparm maltrail
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 stamparm maltrail 3.0.1 及更早版本中发现了一个安全弱点。该漏洞位于组件 Blacklist Endpoint 的文件 中的 函数。对端点的操作可能导致身份验证缺失,且攻击者可远程发起攻击。该漏洞的利用方法已公开,可被用于实际攻击。 升级到版本 3.1 可以解决此问题,对应的补丁标识为 。建议升级受影响的组件。供应商在问题报告当天即修复了该漏洞,在 3.1 版本中,通过将端点限制在已认证的会话中,或引入新的 选项来解决问题。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91002

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
stamparm maltrail 3.0.0 cpe:2.3:a:stamparm:maltrail:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-91002

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91002

登录查看更多情报信息。

Patches & Fixes for CVE-2026-91002 (1)

Proof of Concept for CVE-2026-91002 (1)

Vendor Pages for CVE-2026-91002 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91002

No comments yet


Leave a comment