CVE-2026-91002 Details
Description
A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.
A vulnerability in Stamparm Maltrail versions through 3.0.1 allows for unauthenticated access to the Blacklist Endpoint. This weakness, located in the core/httpd.py file within the _blacklist function, enables remote attackers to retrieve flagged internal source IP addresses without proper authentication. The issue arises because the endpoint lacks authentication checks, exposing sensitive metadata about monitored hosts. The vulnerability has been publicly exploited, but upgrading to version 3.1 effectively resolves the issue by requiring authentication or using the new Blacklist_ALLOWLIST option.
Users are advised to upgrade to Stamparm Maltrail version 3.1 or later, where this vulnerability has been fixed. The 3.1 release includes a changelog entry indicating the addition of authentication requirements for the Blacklist Endpoint, similar to those already in place for the '/fail2ban' endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/simyat/fd48e9c257ab95405c109aec575977f1 | [email protected] | ExploitRemedy |
| https://github.com/stamparm/maltrail/ | [email protected] | Vendor |
| https://github.com/stamparm/maltrail/commit/d95868dff3da4d3bd4f942837a26cb7c73a797ae | [email protected] | Source CodeVendor |
| https://github.com/stamparm/maltrail/releases/tag/3.1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-91002 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/931699 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403583 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403583/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| stamparm Maltrail | <= 3.0.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion