bunkerweb · Issues· 173 open
Open on GitHubLocally synced open issues (discussions stay on GitHub)
- #3936
[BUG] The custom SERVER_HTTP config does not override the header because it is injected outside the reverse proxy location block.
bugconfigcorenext minorUpdated Sep 18, 2026 - #3923
[BUG] Basic Auth won't activate
bugneed more infoUpdated Sep 18, 2026 - #3930
Tar member pre-validation does not account for symlink chains, allowing extraction outside the destination on runtimes without the native tarfile filter
bugsecuritycoreUpdated Sep 18, 2026 - #3916
[BUG] Reports always show "unknown" reason
bugcorenext minorUpdated Sep 18, 2026 - #3927
[BUG] LETS_ENCRYPT_PASSTHROUGH should imply adding `^/.well-known/acme-challenge/` to WHITELIST_URI
bugcorenext minorUpdated Sep 18, 2026 - #3892
Default error page is 139 KB with 40 KB of duplicated inline SVG, served on every intercepted error
performancecoreUpdated Sep 18, 2026 - #3891
ModSecurity audit logging: ~37 lines / ~5 KB written per blocked request, SecAuditLogType not configurable
enhancementcorenext minorUpdated Sep 18, 2026 - #3326
[BUG] robust wildcard certificate naming
bugcorenext minorUpdated Sep 18, 2026 - #3251
[BUG] Lets Encrypt profiles: update Limits in code/readme
bugcorenext minorUpdated Sep 18, 2026 - #3636
[BUG] issues in Bunkernet Register
bugcorenext minorUpdated Sep 18, 2026 - #3303
[BUG] Scheduler config saver failures and manual plugin handling issues with poor observability
bugschedulernext minorUpdated Sep 18, 2026 - #3893
[BUG] Cannot create new service
buguinext minorUpdated Sep 14, 2026 - #173
Refactor of custom configurations
bugcorenext majorUpdated Sep 14, 2026 - #3552
[BUG] Blocked requests on stream services are not reported in REPORTS
bugcorenext majorUpdated Sep 14, 2026 - #2359
[BUG] The CSRF token expires quickly.
buguinext minorUpdated Sep 14, 2026