OPNSense

opnsense.org
OPNSense

Enterprise firewall and router for protecting networks, built on the FreeBSD system.

Open Source

OPNSense Source Code

Author

opnsense

Description

OPNsense GUI, API and systems backend

#api#bsd#captive-portal#firewall#gui#hacktoberfest#ips#proxy#routing#shaping#vpn

Homepage

https://opnsense.org/

License

BSD-2-Clause

Created

13 Dec 14

Last Updated

28 Jul 26

Latest version

27.1.a

Primary Language

PHP

Size

101,570 KB

Stars

4,545

Forks

974

Watchers

4,545

Language Usage

Language Usage

Star History

Star History

Recent Commits

  • Ad Schellevis (28 Jul 26)

    Auth/SSOProviders - add glue for https://github.com/opnsense/core/issues/10433

  • Ad Schellevis (26 Jul 26)

    configd: further restrict configd actions to root and wwwonly for more sensitive actions (stopping services, reading certain data, ..) that won't be scheduled anyway and should have no other consumers. addition to https://github.com/opnsense/core/commit/a313cbd5bdcfc3c9d4a55704fcdb8bbcf7182069 In the long run we might consider swapping the defaults, but since the chance of regressions is rather larger and most callouts aren't that problematic anyway, opt for explicit elevated rights for now.

  • Ad Schellevis (25 Jul 26)

    Firewall: NAT: Destination NAT - fix missing "well-known" in local-port, closes https://github.com/opnsense/core/issues/10612 While here, also suppress a php warning for an non-existing entry.

  • Franco Fichtner (24 Jul 26)

    system: support RSA 7680 PR: https://forum.opnsense.org/index.php?topic=52537.0

  • Monviech (24 Jul 26)

    MVC: UI: Parenthesize the filtered static value so Volt applies the default before negating it, avoiding undefined array key warnings. (#10608)

  • Monviech (24 Jul 26)

    MVC: UI: base_tabs_header fix tab activation (#10606)

  • Franco Fichtner (24 Jul 26)

    network time: restart change for #9352

  • Franco Fichtner (24 Jul 26)

    system: configure dhcp via backend, move dns over #9352

  • Franco Fichtner (24 Jul 26)

    system: move backup restore to /var/lib/php/tmp #9352

  • Franco Fichtner (24 Jul 26)

    system: add dns reconfigure #9352

  • Franco Fichtner (24 Jul 26)

    system: switch timezone and hostname restarts #9352

  • Franco Fichtner (24 Jul 26)

    system: replace kernel/powerd restart now that it works #9352

  • Franco Fichtner (24 Jul 26)

    system: change approach due to MVC entanglement Frist approach did not work. Make it a bit more obvious.

  • Monviech (24 Jul 26)

    Firewall: Rules and NAT: Group invalid rules to the end of the ruleset. These rules are skipped by PF processing because they do not have a valid interface. (#10550) --------- Co-authored-by: Stephan de Wit <[email protected]>

  • Franco Fichtner (24 Jul 26)

    system: add hidden services so they can be operated by pluginctl -s #9352 For now that's kernel and powerd. Eventually these workarounds will go away anyway.

  • Franco Fichtner (24 Jul 26)

    system: replace login/sysctl restart for #9352

  • Franco Fichtner (24 Jul 26)

    system: switch resolver reload for #9352

  • Stephan de Wit (24 Jul 26)

    aliases: enable virtualDOM here and refactor commands

  • Monviech (24 Jul 26)

    MVC:ui Fix collapsible form section rendering in base_form.volt in f8c0ba6 (#10604)

  • Franco Fichtner (24 Jul 26)

    system: replace cron restart in legacy pages #9352 This probably slows down execution, but either we solve this later on or just live with it as these pages are going away eventually.

  • Franco Fichtner (24 Jul 26)

    system: move old dirty file markers to /var/lib/php/tmp #9352

  • Franco Fichtner (24 Jul 26)

    www: avoid filter_configure() to make backend call less obscure #9352 We need to switch all other configuration to the backend as well so it makes sense to deprecate filter_configure() and later match all the other configuration functions using similar backend calls.

  • Ad Schellevis (24 Jul 26)

    MVC:ui - regression in 3d9cccfe4038802807219621ddd49cf668a05144, breaks collapse/static keywords, should fix https://github.com/opnsense/core/issues/10601

  • Stephan de Wit (24 Jul 26)

    bootgrid: classname can depend on state, accept a callback function

  • Franco Fichtner (24 Jul 26)

    mvc: stale import in backup

  • Franco Fichtner (24 Jul 26)

    mvc: fix stale imports in core

  • Franco Fichtner (24 Jul 26)

    mvc: fix stale imports in base

  • Franco Fichtner (24 Jul 26)

    mvc: fix stale imports in diagnostics

  • Franco Fichtner (24 Jul 26)

    firewall: fix stale imports

  • Franco Fichtner (24 Jul 26)

    mvc: fix imports for Backend

OPNSense Security

4.8/10

Repo Security Summary

Updated 13 Jul 26

  • Maintained 10/10
  • Packaging N/A
  • Code-Review 2/10
  • Token-Permissions N/A
  • Dangerous-Workflow N/A
  • Security-Policy 10/10
  • CII-Best-Practices 0/10
  • License 10/10
  • Signed-Releases N/A
  • Binary-Artifacts 10/10
  • Branch-Protection 0/10
  • Pinned-Dependencies N/A
  • SAST 0/10
  • Fuzzing 0/10

Security Advisories (24)

  • medium Patched CVSS 5.3

    GHSA-h4qj-j2x9-q553 Unauthenticated lighttpd request-body disk exhaustion

  • high Patched CVSS 7.6

    GHSA-vw8q-pqq7-2q7v Manual Config::save() paths bypass user-config-readonly enforcement

  • medium Patched CVSS 5.9

    GHSA-rw63-4hw9-p4v7 OpenVPN Client Export Utility users can export private keys for unlisted certificate refs

  • medium Patched CVSS 6.3

    GHSA-jm2f-ch62-rpxr Multiple Stored XSS

  • high Patched CVSS 7.1

    GHSA-p9pr-782r-w2xw Direct comma-separated user privileges bypass OPNsense MVC read-only write protection

  • high Patched CVSS 8.1

    CVE-2026-63442 Log Forgery via Login Username CRLF in WebGUI Authentication → Pf Table IP Blocking

  • medium Patched CVSS 5.2

    CVE-2026-58394 Stored XSS in Administration Settings via Certificate Description

  • medium Patched CVSS 4.3

    CVE-2026-58395 XPath injection in MVC safe-delete

  • medium Patched CVSS 5.4

    CVE-2026-58392 Stored XSS in Services: NTP GPS

  • medium Patched CVSS 5.4

    CVE-2026-58391 Stored XSS in Firewall Rules/NAT pages via a HTML-attribute breakout

  • critical Patched CVSS 9.9

    CVE-2026-57155 Root RCE via Arbitrary File Write in GeoIP Alias Importer

  • high Patched CVSS 8

    CVE-2026-58390 Stored XSS to root RCE via OpenVPN client common_name in status views

  • high Patched CVSS 8.1

    GHSA-m4m3-v627-wgc2 Stored Cross-Site Scripting (XSS) via TrafficShaper description in legacy PHP firewall rules page

  • medium Patched CVSS 5.9

    CVE-2026-58393 OpenVPN Client Specific Override common_name allows path traversal in generated CSO files

  • high Patched CVSS 8.1

    GHSA-33q4-wcv7-r8fr Trust certificate and CA refids allow path traversal during IPsec file generation

  • high Patched CVSS 8.1

    CVE-2026-57154 Configuration line injection via multiple GUI text fields

  • high Patched CVSS 7.1

    CVE-2026-53582 XPATH Injection can disclose any secret in config.xml

  • critical Patched CVSS 9

    CVE-2026-53581 ntp: write path traversal

  • critical Patched CVSS 9.1

    CVE-2026-44194 RCE on user managment

  • critical Patched

    CVE-2026-45158 Command Injection via Attacker-Controlled DHCP Config

  • critical Patched CVSS 9.1

    CVE-2026-44193 RCE via XMLRPC endpoint using `opnsense.restore_config_section` method

  • medium Patched CVSS 5.3

    CVE-2026-44195 Authentication lockout bypass

  • high Patched CVSS 8.2

    CVE-2026-34578 LDAP Injection via Unsanitized Username in Authentication

  • medium Patched CVSS 6.3

    CVE-2026-30868 Cross-Site Request Forgery (CSRF) in opnsense/core

OPNSense Website

Website

OPNsense® is an open source, feature rich firewall and routing platform, offering cutting-edge network protection. - OPNsense

We’ve made digital security accessible to everyone. With our free OPNsense® platform, you get all the features of expensive commercial firewalls and more. Enjoy open and verifiable sources in a product developed with and for a large user community.

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address 89.149.225.137
  • Location Amsterdam, Noord-Holland, Netherlands (Kingdom of the), EU
  • ISP Leaseweb Netherlands B.V.
  • ASN AS60781

Associated Countries

  • US US
  • NL NL

Safety Score

Website marked as safe

100%

Blacklist Check

opnsense.org was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

OPNSense Reviews

More Firewalls

About the Data: OPNSense

Change History

  • Amended (github) by @lissy93 #608
  • Renamed previously: OpenSense from Networking › Firewalls by @HammyHavoc #202

API

You can access OPNSense's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/opnsense

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share OPNSense

Help your friends compare Firewalls, and pick privacy-respecting software and services.
Share OPNSense and Awesome Privacy with your network!

View Firewalls (14)