CVE-2026-91002: stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication
A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new BlacklistALLOWLIST option.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
stamparm maltrail Blacklist Endpoint httpd.py _blacklistto a version that resolves this vulnerability.Fixed in 3.1Patch d95868dff3da4d3bd4f942837a26cb7c73a797ae
Event History
Frequently Asked Questions
Which deployments are exposed?
Maltrail versions up to 3.0.1 are affected where the Blacklist Endpoint implemented by _blacklist in core/httpd.py is reachable remotely.
Does exploitation require credentials or user interaction?
No. The issue is missing authentication, and the supplied vector indicates remote exploitation with no privileges or user interaction required.
What should be done if the endpoint must remain available?
Upgrade to Maltrail 3.1. The fix gates the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.
Is public exploit code available?
Yes. The vulnerability data states that an exploit has been made publicly available.