BunkerWeb
bunkerweb.ioSelf-HostedBunkerWeb is an open-source Next-Generation Web Application Firewall (WAF). It provides easy protection for your web services and is designed to remain secure by default. It integrates seamlessly with modern environments (Docker, Kubernetes, Linux, etc.).
- Homepage:bunkerweb.io
- GitHub:github.com/bunkerity/bunkerweb
- Web info:web-check.xyz/check/bunkerweb.io
BunkerWeb Source Code
Author
Description
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Homepage
https://www.bunkerweb.ioRepository
- LicenseAGPL-3.0
- Created20 Aug 19
- Primary languagePython
- Size1,026,553 KB
- Stars11,054
- Forks649
- Watchers11,054
Top Contributors
@TheophileDiot (7053)
@fl0ppy-d1sk (1982)
@syrk4web (877)
@dependabot[bot] (645)
@thelittlefireman (36)
@Hado-K3n (15)
@tomkolp (14)
@Anadris (12)
@Michal-Koeckeis-Fresel (10)
@lenglet-k (10)
@adren (7)
@Copilot (7)
@gin-gitaxias (7)
@wiseweb-works (4)
@Marvo2011 (4)
@Ayushsinha322 (4)
@jbbandos (3)
@mromanelli9 (3)
@Simonmiz (3)
@TomVivant (3)
@AxyFr (3)
@rayshoo (3)
@ajarmoszuk (3)
@sachin-vcs (3)
@Brawdunoir (2)
@spwoodcock (2)
@MageInt (2)
@robotter112 (2)
@nimro27 (2)
@Crazy3lf (2)
@aptkzzz (1)
@xabru (1)
@vepito (1)
@peterkimzz (1)
@killmasta93 (1)
@jonas0b1011001 (1)
@immanuwell (1)
@harshadkhetpal (1)
@ZILosoft (1)
@Arakmar (1)
@teguh02 (1)
@PathToLife (1)
@Nakinox (1)
@Myzel394 (1)
@1t1sCooL (1)
@mevenG (1)
@Pizmovc (1)
@Kn-ut99 (1)
@eltociear (1)
@HongyiHank (1)
@FacundoAcevedo (1)
@ff6347 (1)
@cleverguns (1)
@Ablablab (1)
@kovacs-andras (1)
@YouKyi (1)
@aizatto (1)
Recent Commits
Théophile Diot(21 Sept 26)
Road to 1.6.15 🚀
Théophile Diot(19 Sept 26)
Merge pull request #3940 from bunkerity/dev fix(ci): pin Ansible target interpreter
TheophileDiot(19 Sept 26)
fix(ci): pin Ansible target interpreter
Théophile Diot(19 Sept 26)
Merge pull request #3939 from bunkerity/dev Merge branch 'dev' into branch 'staging'
TheophileDiot(19 Sept 26)
fix(ci): correct Ansible runner vars
Théophile Diot(19 Sept 26)
Merge pull request #3938 from bunkerity/dev Merge branch 'dev' into branch 'staging'
TheophileDiot(19 Sept 26)
Merge branch 'dev' of https://github.com/bunkerity/bunkerweb into dev
TheophileDiot(19 Sept 26)
chore(linux): drop Fedora 43 NGINX 1.30.4 exception
Théophile Diot(19 Sept 26)
Merge pull request #3925 from bunkerity/dependabot/github_actions/dev/pullfrog/pullfrog-0.1.79 deps/gha: bump pullfrog/pullfrog from 0.1.78 to 0.1.79
Théophile Diot(19 Sept 26)
Merge pull request #3926 from bunkerity/dependabot/github_actions/dev/getplumber/plumber-0.4.63 deps/gha: bump getplumber/plumber from 0.4.62 to 0.4.63
Théophile Diot(19 Sept 26)
Merge pull request #3933 from bunkerity/dependabot/github_actions/dev/docker/build-push-action-7.4.0 deps/gha: bump docker/build-push-action from 7.3.0 to 7.4.0
Théophile Diot(19 Sept 26)
Merge pull request #3934 from bunkerity/dependabot/github_actions/dev/docker/setup-qemu-action-4.4.0 deps/gha: bump docker/setup-qemu-action from 4.3.0 to 4.4.0
Théophile Diot(19 Sept 26)
Merge pull request #3935 from bunkerity/dependabot/github_actions/dev/ruby/setup-ruby-1.323.0 deps/gha: bump ruby/setup-ruby from 1.321.0 to 1.323.0
Théophile Diot(19 Sept 26)
Merge pull request #3932 from bunkerity/dependabot/terraform/tests/terraform/dev/scaleway/scaleway-2.83.0 deps/terraform: bump scaleway/scaleway from 2.82.0 to 2.83.0 in /tests/terraform
TheophileDiot(19 Sept 26)
docs(features): sync the gRPC and reverse proxy sections
TheophileDiot(19 Sept 26)
feat(reverseproxy): expose upstream mutual TLS and harden validation
TheophileDiot(19 Sept 26)
feat(grpc): match reverse proxy configurability
TheophileDiot(18 Sept 26)
chore(alembic): Generate migration files for the 1.6.15
TheophileDiot(18 Sept 26)
Prepare for 1.6.15 🚀
TheophileDiot(18 Sept 26)
docs(kubernetes): the policy covers the whole internal API, on both listeners
TheophileDiot(18 Sept 26)
docs(kubernetes): note the HTTPS port in the instance API policy
TheophileDiot(18 Sept 26)
feat(security): require a token on the instance API and restrict its ingress
TheophileDiot(18 Sept 26)
docs(api): destination grant on config moves, plugin-bound cache deletes
TheophileDiot(18 Sept 26)
core(deps): Update python deps
TheophileDiot(18 Sept 26)
fix(api,ui): only mark a plugin changed when its cache row was deleted
TheophileDiot(18 Sept 26)
fix(api): authorize the destination service on a custom-config move
TheophileDiot(18 Sept 26)
fix(reverseproxy): allow overriding generated headers
TheophileDiot(18 Sept 26)
docs(features): anchor path rules below the prefix
TheophileDiot(18 Sept 26)
docs(web-ui): OSS roles are read and write only
TheophileDiot(18 Sept 26)
fix(ui): brand the reports investigate button as CrowdSec
BunkerWeb Security
Security Advisories (16)
- highPatchedCVSS 8.8
GHSA-xcv3-gjwr-rwxwUnauthenticated RCE via the BunkerWeb Worker API in the Official Kubernetes Sidecar Configuration
- lowPatchedCVSS 2.7
GHSA-vqvw-37gh-5w49Cross-Service Custom Configuration Move via Unauthorized Destination
- mediumPatchedCVSS 4.3
GHSA-j2mq-vqhg-c5mrCache Deletion Crosses the Job-Run Permission Boundary
- lowPatchedCVSS 3.8
GHSA-7w87-8gxh-2x99 Service Conversion Permission Bypass in the Fine-Grained API ACL
- highPatchedCVSS 8.6
GHSA-cvfx-2ffg-cqmjBypass filename rules via `filename*=` parameter
- mediumPatchedCVSS 5.4
GHSA-j63f-j59c-q626TOTP recovery codes can be rotated before second-factor validation
- highPatchedCVSS 8.8
GHSA-cc8g-89qq-j9vmAuthenticated remote code execution via malicious plugin upload — arbitrary Python code executed via SourceFileLoader
- mediumPatchedCVSS 5.4
CVE-2026-61718Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes
- lowPatchedCVSS 3.8
GHSA-rwch-jhxx-cx5fImproper Hostname Validation Allows Outbound Request Redirection (Potential SSRF) via @ Injection in Instance Registration
- mediumPatched
GHSA-78p8-cwrf-35r2CI: staging reusable inherits all secrets; 14 reusable workflows lack explicit permissions on release/build paths
- mediumPatched
CVE-2026-54728Authenticated privilege escalation via Host header handling in BunkerWeb UI and API
- highPatchedCVSS 8.8
GHSA-4wcx-xgv7-fjq8Security Vulnerability Report: Path Traversal in UI Plugin Refresh
- mediumPatchedCVSS 5.9
CVE-2026-75514rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, whitelist and antibot
- highPatchedCVSS 8.1
GHSA-79fm-4xj6-pp5gArbitrary File Write/Delete via Path Traversal in BunkerWeb Let's Encrypt API
- lowPatchedCVSS 3.5
CVE-2025-8066CVE-2025-8066 – Open Redirect vulnerability in BunkerWeb UI 1.6.X (< 1.6.4)
- lowPatched
CVE-2024-53264Open Redirect Vulnerability in Loading Page
BunkerWeb Website
Website
BunkerWeb - The open-source Web Application Firewall (WAF)
Fool attackers and protect your web services with BunkerWeb, the open-source and next-gen Web Application Firewall (WAF).
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address51.159.125.247
- Hostname51-159-125-247.rev.poneytelecom.eu
- LocationParis,Ile-de-France,France,EU
- ISPScaleway SAS
- ASNAS12876
Associated Countries
NL
FR
Safety Score
Website marked as safe
100%
Blacklist Check
www.bunkerweb.io was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
BunkerWeb Reviews
More Firewalls
AFWall+
(Android - Rooted)
xdaforums.com/t/5-0-root-3-6-0-afwall-iptables-firewall-28-aug-2023.1957231Android Firewall+ (AFWall+) is an advanced iptables editor (GUI) for rooted Android devices, which provides very fine-grained control over which Android apps are allowed to access the network.
Open source GUI firewall for Linux, allowing you to block internet access for certain applications. Supports both simple and advanced mode, GUI and CLI options, very easy to use, lightweight/ low-overhead, under active maintenance and backed by a strong community.
IPFire is a hardened, versatile, state-of-the-art Open Source firewall based on Linux. Easy to install on a raspberry Pi, since it is lightweight and heavily customizable.
A very polished application firewall, allowing you to easily manage internet connections on a per-app basis. (Mac OS)
Not Open SourceFirewall app for iPhone, allowing you to block any connection to any domain.
Not Open SourceFree, open source macOS firewall. It aims to block unknown outgoing connections, unless explicitly approved by the user.
Provides simple and advanced ways to block access to the internet. Applications and addresses can individually be allowed or denied access to Wi-Fi and/or mobile connection.
Makes internet connections from all apps visible, allowing you to block or manage traffic on a per-app basis. GNU/Linux port of the Little Snitch application firewall.
Enterprise firewall and router for protecting networks, built on the FreeBSD system.
An open-source ad-blocker and firewall app for Android 6+ (does not require root).
An open source firewall tool for Linux that builds upon the Netfilter system built into the Linux kernel, making it easier to manage more complex configuration schemes with iptables.
Tool to control Windows Filtering Platform (WFP), in order to configure detailed network activity on your PC. (Windows)
The ufw (Uncomplicated Firewall) is a GUI application and CLI, that allows you to configure a firewall using
iptablesmuch more easily.
About the Data: BunkerWeb
Change History
- Added #378
Edit BunkerWeb Data
You can edit BunkerWeb's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access BunkerWeb's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/bunkerwebThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share BunkerWeb
Help your friends compare Firewalls, and pick privacy-respecting software and services.
Share BunkerWeb and Awesome Privacy with your network!