Description
A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Missing authentication for the blacklist endpoint enabling unauthenticated modification or enquiry of the blacklist
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the _blacklist function of maltrail's core/httpd.py, allowing remote execution of a request that bypasses authentication checks. This permits an unauthenticated attacker to modify or query the blacklist without authorization, potentially enabling further malicious network activity. The weakness is classified as CWE-287 (Authentication Failure) and CWE-306 (Missing Authentication for Critical Function).

Affected Systems

Stamparm's maltrail versions up to and including 3.0.1 are affected. The flaw exists in the Blacklist Endpoint component; all deployments running these releases are susceptible until the upgrade to 3.1, which gates the endpoint with authenticated sessions or the new Blacklist_ALLOWLIST option.

Risk and Exploitability

The CVSS base score of 6.9 indicates moderate impact, and the EPSS score of less than 1 % suggests low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can target any machine exposing the unsanitized / is possible; no additional privileges are required beyond standard network connectivity.

Generated by OpenCVE AI on September 17, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade maltrail to version 3.1 orlist Endpoint.
  • Verify that the Blacklist Endpoint is protected by authentication or that the Blacklist_ALLOWLIST option is enabled to restrict access.
  • Regularly audit blacklist modifications and monitor logs for unauthorized requests to the endpoint.

Generated by OpenCVE AI on September 17, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.
Title stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication
First Time appeared Stamparm
Stamparm maltrail
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:stamparm:maltrail:*:*:*:*:*:*:*:*
Vendors & Products Stamparm
Stamparm maltrail
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Stamparm Maltrail
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:53:57.405Z

Reserved: 2026-09-14T15:38:40.042Z

Link: CVE-2026-91002

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:11.863Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:17:00.643

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-91002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function