CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-0650

Critical · CVSS 9.3

github.com/openflagr/flagr — Authentication bypass via HTTP middleware path normalization whitelist logic

CVSS
9.3
nvd
EPSS
0.44%
35th pct
KEV
No
Class
oss containerizable
CWE-306, CWE-425

Description

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

Search profile — drives PoC discovery

Symbols whitelistpath normalizationHTTP middlewareauthentication bypassprefix whitelistfeature flagsAPI endpoints
Keywords CVE-2026-0650openflagrflagrauthentication bypasspath normalizationmiddleware whitelistCWE-306CWE-4251.1.18prefix whitelist bypassOpenFlagr PoC
Versions: <=1.1.18

Affected packages

Go github.com/openflagr/flagr 0 → 0.0.0-20251009103504-fe83dc87aa40

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z