Back

CRITICAL

OpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization

Published Jan 7, 2026

Description

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 7, 2026
Updated Jul 14, 2026
Reserved Jan 6, 2026
CISA Vulnrichment
Updated Jan 7, 2026
NVD
Status Deferred
Modified Jul 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Jan 7, 2026
Updated Jul 14, 2026
Exploited since n/a
EUVD-2026-1181 GHSA-RWP9-5G7Q-73Q3