| { |
| "schema_version": "1.3.1", |
| "id": "GO-2026-4286", |
| "modified": "0001-01-01T00:00:00Z", |
| "published": "0001-01-01T00:00:00Z", |
| "aliases": [ |
| "CVE-2026-0650", |
| "GHSA-rwp9-5g7q-73q3" |
| ], |
| "summary": "OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr", |
| "details": "OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr", |
| "affected": [ |
| { |
| "package": { |
| "name": "github.com/openflagr/flagr", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "0" |
| }, |
| { |
| "fixed": "0.0.0-20251009103504-fe83dc87aa40" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": {} |
| } |
| ], |
| "references": [ |
| { |
| "type": "ADVISORY", |
| "url": "https://github.com/advisories/GHSA-rwp9-5g7q-73q3" |
| }, |
| { |
| "type": "ADVISORY", |
| "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0650" |
| }, |
| { |
| "type": "FIX", |
| "url": "https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570" |
| }, |
| { |
| "type": "WEB", |
| "url": "https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass" |
| }, |
| { |
| "type": "WEB", |
| "url": "https://github.com/openflagr/flagr/releases/tag/1.1.19" |
| }, |
| { |
| "type": "WEB", |
| "url": "https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization" |
| } |
| ], |
| "database_specific": { |
| "url": "https://pkg.go.dev/vuln/GO-2026-4286", |
| "review_status": "UNREVIEWED" |
| } |
| } |