CVE-2026-91002: stamparm maltrail Blacklist Endpoint httpd.py _blacklist missing authentication

Published Sep 15, 2026
·
Updated

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.1 is able to resolve this issue. This patch is called d95868dff3da4d3bd4f942837a26cb7c73a797ae. It is suggested to upgrade the affected component. The vendor fixed the issue the same day it was reported, in version 3.1, by gating the endpoint on an authenticated session or the new BlacklistALLOWLIST option.

Affected Software

2 affected components
stamparm maltrail<=3.0.1
maltrail=3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade stamparm maltrail Blacklist Endpoint httpd.py _blacklist to a version that resolves this vulnerability.

    Fixed in 3.1Patch d95868dff3da4d3bd4f942837a26cb7c73a797ae

Event History

Sep 15, 2026
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Maltrail versions up to 3.0.1 are affected where the Blacklist Endpoint implemented by _blacklist in core/httpd.py is reachable remotely.

2

Does exploitation require credentials or user interaction?

No. The issue is missing authentication, and the supplied vector indicates remote exploitation with no privileges or user interaction required.

3

What should be done if the endpoint must remain available?

Upgrade to Maltrail 3.1. The fix gates the endpoint on an authenticated session or the new Blacklist_ALLOWLIST option.

4

Is public exploit code available?

Yes. The vulnerability data states that an exploit has been made publicly available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203