VDB
GO-2026-4286
GO-2026-4286
PUBLISHED
CVSS 9.300000190734863 CRITICAL
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | openflagr/flagr | 0, 0 |
Timeline
- Jan 12, 2026 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/advisories/GHSA-rwp9-5g7q-73q3 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-0650 advisory
- https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass url
- https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization url
- https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570 fix
- https://github.com/openflagr/flagr/releases/tag/1.1.19 fix