CRITICAL
OpenFlagr <= 1.1.18 Authentication Bypass via Prefix Whitelist Path Normalization
Published Jan 7, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.52%
Description
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.
Affected products
-
- Version 0StatusaffectedConstraints<=1.1.18
- Version
No data.
No data.
No Red Hat product state for this CVE.
github.com/openflagr/flagr
Go
Introduced 0 Fixed 0.0.0-20251009103504-fe83dc87aa40
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/openflagr/flagr | 0 | 0.0.0-20251009103504-fe83dc87aa40 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass technical-descriptionexploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1181 Advisory
- https://github.com/advisories/GHSA-rwp9-5g7q-73q3 Advisory
- https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570
- https://github.com/openflagr/flagr/releases/tag/1.1.19 release-notespatch
- https://nvd.nist.gov/vuln/detail/CVE-2026-0650
- https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jan 7, 2026
Updated Jul 14, 2026
Reserved Jan 6, 2026
Link CVE-2026-0650
CISA Vulnrichment
Updated Jan 7, 2026
ENISA EUVD
EUVD-2026-1181 GHSA-RWP9-5G7Q-73Q3 Assigner VulnCheck
Published Jan 7, 2026
Updated Jul 14, 2026
Exploited since n/a
Link EUVD-2026-1181