Fail2ban is a widely deployed intrusion-prevention utility that monitors logs and dynamically blocks failed authentication attempts across diverse server environments, making it a foundational component in many Linux and Unix security stacks despite its modest CVE volume. Its vulnerability profile centers on the single, heavily reused fail2ban product and recurs through input-validation flaws, authentication weaknesses, code-injection conditions, and symlink-resolution issues—exposures characteristic of a log-parsing engine that must handle untrusted input while managing file system operations with elevated privilege. Public exploit code has been developed for vulnerabilities in this class, reflecting the utility's visibility and appeal as a target for privilege-escalation and evasion attacks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fail2ban over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4321MEDIUM fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by a | Aug 14, 2007 | 6.8 | 34 | NO | YES |
CVE-2021-32749HIGH fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability | Jul 16, 2021 | 8.1 | 28 | NO | NO |
CVE-2012-5642HIGH server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action | Dec 31, 2012 | 7.5 | 26 | NO | NO |
CVE-2013-7177MEDIUM config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail a | Feb 1, 2014 | 5.0 | 19 | NO | NO |
CVE-2013-7176MEDIUM config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address | Feb 1, 2014 | 5.0 | 19 | NO | NO |
CVE-2009-5023MEDIUM The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitr | Jun 10, 2014 | 4.7 | 18 | NO | NO |
CVE-2013-2178MEDIUM The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote | Aug 28, 2013 | 5.0 | 15 | NO | NO |
CVE-2006-6302MEDIUM fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by | Dec 6, 2006 | 5.0 | 15 | NO | NO |
CVE-2009-0362MEDIUM filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted | Feb 13, 2009 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fail2ban.
Media articles that mention a CVE ID that affects a product developed by Fail2ban — matched by CVE ID, not by vendor name.