---
id: CVE-2026-62314
aliases:
  - GHSA-6wcg-mqvh-fcvg
title: 'Anubis: Policy bypass via client controlled X-Original-URI header'
summary: 'Anubis: Policy bypass via client controlled X-Original-URI header'
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
vendor: TecharoHQ
product: github.com/TecharoHQ/anubis
ecosystem: go
affected:
  - 'github.com/TecharoHQ/anubis >= 1.22.0, < 1.26.0'
patched:
  - github.com/TecharoHQ/anubis 1.26.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:30:39.766334532Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6wcg-mqvh-fcvg'
references:
  - url: >-
      https://github.com/TecharoHQ/anubis/security/advisories/GHSA-6wcg-mqvh-fcvg
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62314'
  - url: 'https://github.com/TecharoHQ/anubis/pull/1630'
  - url: >-
      https://github.com/TecharoHQ/anubis/commit/276b537776b281b1c4e01421435bc03ade3d8fc4
  - url: 'https://github.com/TecharoHQ/anubis'
  - url: 'https://github.com/TecharoHQ/anubis/releases/tag/v1.26.0-pre1'
  - url: 'https://github.com/advisories/GHSA-6wcg-mqvh-fcvg'
tags:
  - osv
  - go
  - ghsa
epss: 0.00464
epssPercentile: 0.37933
cwe:
  - CWE-284
ingestedAt: '2026-10-02T18:25:05.832Z'
---

## Overview

Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved.
Affected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015)

The root cause is in `lib/policy/checker.go`, `PathChecker.Check()`:
```go
func (pc *PathChecker) Check(r *http.Request) (bool, error) {
    originalUrl := r.Header.Get("X-Original-URI")
    if originalUrl != "" {
        if pc.regexp.MatchString(originalUrl) {
            return true, nil
        }
    }
    if pc.regexp.MatchString(r.URL.Path) {
        return true, nil
    }
    return false, nil
}
```

The header value comes directly from the client request. The middleware chain never strips it. In reverse proxy mode an attacker fully controls it.
The default policy imports `data/common/keep-internet-working.yaml`, which contains path-only ALLOW rules with no other conditions:

```yaml
- name: well-known
  path_regex: ^/\.well-known/.*$
  action: ALLOW
```

When `X-Original-URI` matches one of those regexes, the rule fires as ALLOW and the request is forwarded upstream without any challenge or JWT check.


# Proof of concept

Normal request, gets challenged:
```
curl -s https://anubis.techaro.lol/ | grep -o "<title>.*</title>"
```

Bypass, gets upstream content:
```
curl -s -H "X-Original-URI: /.well-known/x" https://anubis.techaro.lol/ | grep -o "<title>.*</title>"
```

The first command returns the Anubis challenge page title. The second returns the real site title directly, with no cookie set and no challenge issued. Verified live against anubis.techaro.lol.

# Suggested fix
The fix should probably be to strip the header from incoming client requests in the middleware chain before policy evaluation. In `auth_request` mode the header is set by the proxy after Anubis processes the middleware, so stripping it at ingress does not break that deployment mode.

## Affected packages

- `github.com/TecharoHQ/anubis >= 1.22.0, < 1.26.0`

## Remediation

Upgrade to a patched release:

- `github.com/TecharoHQ/anubis 1.26.0`
