{"apiVersion":"1.0","identifier":"CVE-2026-75514","description":"BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix matches in IGNORE_RDNS, GREYLIST_RDNS, and ANTIBOT_IGNORE_RDNS without using get_ips to confirm that the hostname resolves to the client address. An unauthenticated remote attacker who controls a PTR record can spoof a trusted suffix to bypass rDNS-based blacklisting, gain greylist treatment, or skip an antibot challenge. This issue is fixed in version 1.6.13.","publishedAt":"2026-08-20T19:17:03","lastModifiedAt":"2026-08-20T19:17:03","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75514","cvssScore":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","epssProbability":0.00462,"riskScore":0.61,"affectedProduct":"BunkerWeb","affectedVersions":"<1.6.13","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-75514","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-75514","en":"https://www.redsauce.net/en/cves/CVE-2026-75514","fr":"https://www.redsauce.net/fr/cves/CVE-2026-75514","pt":"https://www.redsauce.net/pt/cves/CVE-2026-75514","de":"https://www.redsauce.net/de/cves/CVE-2026-75514","sk":"https://www.redsauce.net/sk/cves/CVE-2026-75514","el":"https://www.redsauce.net/el/cves/CVE-2026-75514"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-75514"}}