Skip to content

UUSEC WAF

Network Security

A free, high‑performance web application firewall with AI/semantic detection and three‑layer defense (traffic, system, runtime)

Shell Latest v7.2.3 · 4d ago Security brief →

Features

  • Intelligent 0‑day defense using machine‑learning anomaly detection
  • Ultimate CDN acceleration with regex‑based cache cleaning surpassing nginx's commercial version
  • Dual‑layer proactive defense via HIPS (host) and RASP (runtime) engines

Recent releases

View all 14 releases →
Config change
v7.2.3 Mixed
Auth

Basic auth plugin + IP threat fix

Upgrade now
v7.2.2 Security relevant
Dependencies

CVE-2026-9256 fix

Upgrade now
v7.2.1 Security relevant
Dependencies

nginx vulnerability fixes

v7.2.0 Breaking risk
Breaking changes
  • Direct upgrade from previous versions is unsupported; migration required.
Notable features
  • Log-only rule functionality added with constants waf.RULE_BLOCK, waf.RULE_ALLOW, and waf.RULE_LOG_ONLY
Full changelog

[!WARNING]
Attention: This version is incompatible with older versions and does not support direct upgrade from previous versions.

Feature Updates:

  • Supports log-only rule functionality, introducing three new rule constants: waf.RULE_BLOCK, waf.RULE_ALLOW, and waf.RULE_LOG_ONLY. When a rule returns these values, they represent block, allow, and log-only actions, respectively.
v7.1.2 Feature
Notable features
  • Add and modify multiple rules to defend against the latest threats
Changelog

Feature Updates:

  • Add and modify multiple rules to defend against the latest threats.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
1,656
Forks
164
Languages
Shell C Lua

Install & Platforms

Install via
docker shell-script
Platforms
linux

Beta — feedback welcome: [email protected]