CVE-2026-75514CWE-350

CVE-2026-75514

Medium · published August 20, 2026

CVSS v3.1
5.9
EPSS
0%
Percentile
38.5
In the wild
Unconfirmed
What it is

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GREYLIST_RDNS, and ANTIBOT_IGNORE_RDNS without using get_ips to confirm that the hostname resolves to the client address. An unauthenticated remote attacker who controls a PTR record can spoof a trusted suffix to bypass rDNS-based blacklisting, gain greylist treatment, or skip an antibot challenge. This issue is fixed in version 1.6.13.

The record
Technical detail
CVSS v3.1
5.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00462 · 38.5th percentile
Weakness
CWE-350 · Reliance on Reverse DNS Resolution for a Security-Critical Action
Published
2026-08-20T23:17Z
References (5)
EPSS history
Timeline
  • 20 AUG 18:31Z
    BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
    cvelistv5