CVE-2026-0650
Critical · CVSS 9.3github.com/openflagr/flagr — Authentication bypass via HTTP middleware path normalization whitelist logic
- CVSS
- 9.3
- nvd
- EPSS
- 0.44%
- 35th pct
- KEV
- No
- Class
- oss containerizable
- CWE-306, CWE-425
Description
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.
Search profile — drives PoC discovery
Symbols whitelistpath normalizationHTTP middlewareauthentication bypassprefix whitelistfeature flagsAPI endpoints
Keywords CVE-2026-0650openflagrflagrauthentication bypasspath normalizationmiddleware whitelistCWE-306CWE-4251.1.18prefix whitelist bypassOpenFlagr PoC
Versions: <=1.1.18
Affected packages
| Go | github.com/openflagr/flagr | 0 → 0.0.0-20251009103504-fe83dc87aa40 |
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z