← Back to CVE search

CVE-2026-45569

Roxy-WI

Description

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 (-Expand validation to block .. in config_file_name and configver for improved security-) added a line in app/modules/config/config.py:462. This is tuple-membership, not substring containment — -..- in (a, b, c) evaluates to True only if any of a, b, c is equal to the literal string -..-. For any realistic path-traversal payload (../../etc/passwd, ..\\..\\etc\\passwd, etc.) the check returns False and the patch silently lets the payload through. At time of publication, there are no publicly available patches.

CVSS 8.1EPSS 0.316%Risk 0.83
View source
Published
2026-06-10 16:17:08
Affected versions
<=8.2.6.4
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N