Nginx · Verynginx · CVE-2018-19991
**Name of the Vulnerable Software and Affected Versions**
VeryNginx version 0.3.3
**Description**
The issue allows remote attackers to bypass the Web Application Firewall feature due to the lack of an error handler for functions such as `get uri args` or `get post args`, which can lead to API misuse.
**Recommendations**
For VeryNginx version 0.3.3, consider implementing a custom error handler to block potential API misuse until a patch is available. As a temporary workaround, review and restrict access to sensitive API endpoints to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.