CVE-2026-45569
- EPSS 0.32%
- Veröffentlicht 10.06.2026 15:38:17
- Zuletzt bearbeitet 11.06.2026 14:16:28
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules...
CVE-2026-45567
- EPSS 0.24%
- Veröffentlicht 10.06.2026 15:37:35
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there...
CVE-2026-45566
- EPSS 0.15%
- Veröffentlicht 10.06.2026 15:36:10
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{reques...
CVE-2026-45565
- EPSS 0.3%
- Veröffentlicht 10.06.2026 15:34:15
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SS...
CVE-2026-45564
- EPSS 0.3%
- Veröffentlicht 10.06.2026 14:04:05
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-ve...
CVE-2026-45563
- EPSS 0.18%
- Veröffentlicht 10.06.2026 14:03:43
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization c...
CVE-2026-45561
- EPSS 0.22%
- Veröffentlicht 10.06.2026 14:03:03
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(...
CVE-2026-45560
- EPSS 0.15%
- Veröffentlicht 10.06.2026 14:02:31
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string ...
CVE-2026-45559
- EPSS 0.23%
- Veröffentlicht 10.06.2026 14:02:09
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path ...
CVE-2026-45558
- EPSS 0.44%
- Veröffentlicht 10.06.2026 14:01:42
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults var...