CVE-2026-45556
- EPSS 0.37%
- Veröffentlicht 10.06.2026 14:00:54
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_...
CVE-2026-45550
- EPSS 0.2%
- Veröffentlicht 10.06.2026 14:00:06
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that ...
CVE-2026-45549
- EPSS 0.2%
- Veröffentlicht 10.06.2026 13:59:41
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — ...
CVE-2026-45552
- EPSS 0.27%
- Veröffentlicht 10.06.2026 13:59:24
- Zuletzt bearbeitet 10.06.2026 19:37:41
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoin...
CVE-2026-33208
- EPSS 0.66%
- Veröffentlicht 24.04.2026 02:10:13
- Zuletzt bearbeitet 27.04.2026 15:16:15
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into...
CVE-2026-33078
- EPSS 0.35%
- Veröffentlicht 24.04.2026 02:05:02
- Zuletzt bearbeitet 27.04.2026 15:10:14
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced ...
CVE-2026-33077
- EPSS 0.43%
- Veröffentlicht 24.04.2026 01:55:43
- Zuletzt bearbeitet 27.04.2026 15:04:44
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.
CVE-2026-33076
- EPSS 0.82%
- Veröffentlicht 24.04.2026 01:52:47
- Zuletzt bearbeitet 27.04.2026 15:03:04
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing in...
CVE-2026-33432
- EPSS 0.42%
- Veröffentlicht 20.04.2026 20:26:52
- Zuletzt bearbeitet 24.04.2026 19:18:10
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied ...
CVE-2026-33431
- EPSS 0.39%
- Veröffentlicht 20.04.2026 20:24:15
- Zuletzt bearbeitet 24.04.2026 19:19:26
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construc...