GO-2026-4286
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/advisories/GHSA-rwp9-5g7q-73q3, https://nvd.nist.gov/vuln/detail/CVE-2026-0650, https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570, https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass, https://github.com/openflagr/flagr/releases/tag/1.1.19, https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization
