OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
02 / AFFECTED SOFTWARE
Affected packages
34 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.
05 / REFERENCES
Further evidence
- https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0650.json
- https://github.com/openflagr/flagr
- https://github.com/openflagr/flagr/releases/tag/1.1.19
- https://nvd.nist.gov/vuln/detail/CVE-2026-0650
- https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization
- https://github.com/advisories/GHSA-rwp9-5g7q-73q3
- https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570