BunkerWeb

bunkerweb.io
BunkerWeb

BunkerWeb is an open-source Next-Generation Web Application Firewall (WAF). It provides easy protection for your web services and is designed to remain secure by default. It integrates seamlessly with modern environments (Docker, Kubernetes, Linux, etc.).

Open Source

BunkerWeb Source Code

Author

bunkerity

Description

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

#antibot#cybersecurity#devops#devsecops#dnsbl#docker#hardening#hosting#kubernetes#letsencrypt#modsecurity#nginx#reverse-proxy#security#security-tuning#swarm#waap#waf#web-application-firewall#web-security

Homepage

https://www.bunkerweb.io

Repository

  • LicenseAGPL-3.0
  • Created20 Aug 19
  • Primary languagePython
  • Size1,026,553 KB
  • Stars11,054
  • Forks649
  • Watchers11,054

Language Usage

Language Usage

Project Health

  • Last commit1 day ago
  • Open issues185
  • Latest releasev1.6.16-rc4

Recent Commits

  • Théophile Diot(21 Sept 26)

    Road to 1.6.15 🚀

  • Théophile Diot(19 Sept 26)

    Merge pull request #3940 from bunkerity/dev fix(ci): pin Ansible target interpreter

  • TheophileDiot(19 Sept 26)

    fix(ci): pin Ansible target interpreter

  • Théophile Diot(19 Sept 26)

    Merge pull request #3939 from bunkerity/dev Merge branch 'dev' into branch 'staging'

  • TheophileDiot(19 Sept 26)

    fix(ci): correct Ansible runner vars

  • Théophile Diot(19 Sept 26)

    Merge pull request #3938 from bunkerity/dev Merge branch 'dev' into branch 'staging'

  • TheophileDiot(19 Sept 26)

    Merge branch 'dev' of https://github.com/bunkerity/bunkerweb into dev

  • TheophileDiot(19 Sept 26)

    chore(linux): drop Fedora 43 NGINX 1.30.4 exception

  • Théophile Diot(19 Sept 26)

    Merge pull request #3925 from bunkerity/dependabot/github_actions/dev/pullfrog/pullfrog-0.1.79 deps/gha: bump pullfrog/pullfrog from 0.1.78 to 0.1.79

  • Théophile Diot(19 Sept 26)

    Merge pull request #3926 from bunkerity/dependabot/github_actions/dev/getplumber/plumber-0.4.63 deps/gha: bump getplumber/plumber from 0.4.62 to 0.4.63

  • Théophile Diot(19 Sept 26)

    Merge pull request #3933 from bunkerity/dependabot/github_actions/dev/docker/build-push-action-7.4.0 deps/gha: bump docker/build-push-action from 7.3.0 to 7.4.0

  • Théophile Diot(19 Sept 26)

    Merge pull request #3934 from bunkerity/dependabot/github_actions/dev/docker/setup-qemu-action-4.4.0 deps/gha: bump docker/setup-qemu-action from 4.3.0 to 4.4.0

  • Théophile Diot(19 Sept 26)

    Merge pull request #3935 from bunkerity/dependabot/github_actions/dev/ruby/setup-ruby-1.323.0 deps/gha: bump ruby/setup-ruby from 1.321.0 to 1.323.0

  • Théophile Diot(19 Sept 26)

    Merge pull request #3932 from bunkerity/dependabot/terraform/tests/terraform/dev/scaleway/scaleway-2.83.0 deps/terraform: bump scaleway/scaleway from 2.82.0 to 2.83.0 in /tests/terraform

  • TheophileDiot(19 Sept 26)

    docs(features): sync the gRPC and reverse proxy sections

  • TheophileDiot(19 Sept 26)

    feat(reverseproxy): expose upstream mutual TLS and harden validation

  • TheophileDiot(19 Sept 26)

    feat(grpc): match reverse proxy configurability

  • TheophileDiot(18 Sept 26)

    chore(alembic): Generate migration files for the 1.6.15

  • TheophileDiot(18 Sept 26)

    Prepare for 1.6.15 🚀

  • TheophileDiot(18 Sept 26)

    docs(kubernetes): the policy covers the whole internal API, on both listeners

  • TheophileDiot(18 Sept 26)

    docs(kubernetes): note the HTTPS port in the instance API policy

  • TheophileDiot(18 Sept 26)

    feat(security): require a token on the instance API and restrict its ingress

  • TheophileDiot(18 Sept 26)

    docs(api): destination grant on config moves, plugin-bound cache deletes

  • TheophileDiot(18 Sept 26)

    core(deps): Update python deps

  • TheophileDiot(18 Sept 26)

    fix(api,ui): only mark a plugin changed when its cache row was deleted

  • TheophileDiot(18 Sept 26)

    fix(api): authorize the destination service on a custom-config move

  • TheophileDiot(18 Sept 26)

    fix(reverseproxy): allow overriding generated headers

  • TheophileDiot(18 Sept 26)

    docs(features): anchor path rules below the prefix

  • TheophileDiot(18 Sept 26)

    docs(web-ui): OSS roles are read and write only

  • TheophileDiot(18 Sept 26)

    fix(ui): brand the reports investigate button as CrowdSec

BunkerWeb Security

Security Advisories (16)

  • highPatchedCVSS 8.8

    GHSA-xcv3-gjwr-rwxwUnauthenticated RCE via the BunkerWeb Worker API in the Official Kubernetes Sidecar Configuration

  • lowPatchedCVSS 2.7

    GHSA-vqvw-37gh-5w49Cross-Service Custom Configuration Move via Unauthorized Destination

  • mediumPatchedCVSS 4.3

    GHSA-j2mq-vqhg-c5mrCache Deletion Crosses the Job-Run Permission Boundary

  • lowPatchedCVSS 3.8

    GHSA-7w87-8gxh-2x99 Service Conversion Permission Bypass in the Fine-Grained API ACL

  • highPatchedCVSS 8.6

    GHSA-cvfx-2ffg-cqmjBypass filename rules via `filename*=` parameter

  • mediumPatchedCVSS 5.4

    GHSA-j63f-j59c-q626TOTP recovery codes can be rotated before second-factor validation

  • highPatchedCVSS 8.8

    GHSA-cc8g-89qq-j9vmAuthenticated remote code execution via malicious plugin upload — arbitrary Python code executed via SourceFileLoader

  • mediumPatchedCVSS 5.4

    CVE-2026-61718Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes

  • lowPatchedCVSS 3.8

    GHSA-rwch-jhxx-cx5fImproper Hostname Validation Allows Outbound Request Redirection (Potential SSRF) via @ Injection in Instance Registration

  • mediumPatched

    GHSA-78p8-cwrf-35r2CI: staging reusable inherits all secrets; 14 reusable workflows lack explicit permissions on release/build paths

  • mediumPatched

    CVE-2026-54728Authenticated privilege escalation via Host header handling in BunkerWeb UI and API

  • highPatchedCVSS 8.8

    GHSA-4wcx-xgv7-fjq8Security Vulnerability Report: Path Traversal in UI Plugin Refresh

  • mediumPatchedCVSS 5.9

    CVE-2026-75514rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, whitelist and antibot

  • highPatchedCVSS 8.1

    GHSA-79fm-4xj6-pp5gArbitrary File Write/Delete via Path Traversal in BunkerWeb Let's Encrypt API

  • lowPatchedCVSS 3.5

    CVE-2025-8066CVE-2025-8066 – Open Redirect vulnerability in BunkerWeb UI 1.6.X (< 1.6.4)

  • lowPatched

    CVE-2024-53264Open Redirect Vulnerability in Loading Page

BunkerWeb Website

Website

BunkerWeb - The open-source Web Application Firewall (WAF)

Fool attackers and protect your web services with BunkerWeb, the open-source and next-gen Web Application Firewall (WAF).

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address51.159.125.247
  • Hostname51-159-125-247.rev.poneytelecom.eu
  • LocationParis,Ile-de-France,France,EU
  • ISPScaleway SAS
  • ASNAS12876

Associated Countries

  • NLNL
  • FRFR

Safety Score

Website marked as safe

100%

Blacklist Check

www.bunkerweb.io was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

BunkerWeb Reviews

More Firewalls

About the Data: BunkerWeb

Change History

Edit BunkerWeb Data

You can edit BunkerWeb's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access BunkerWeb's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/bunkerweb

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share BunkerWeb

Help your friends compare Firewalls, and pick privacy-respecting software and services.
Share BunkerWeb and Awesome Privacy with your network!