AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass
Published Mar 11, 2026
9.8
CRITICALCVSS 3.1
EPSS 0.78%
Description
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is handled by the inner mux, which has no authentication middleware attached. All subsequent HTTP/2 requests on that connection are processed as fully authenticated, regardless of whether any credentials were provided. This vulnerability is fixed in 0.107.73.
Affected products
-
- Version < 0.107.73StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| AdguardTeam | AdGuardHome | n/a |
|
- < 0.107.73
No data.
No Red Hat product state for this CVE.
github.com/AdguardTeam/AdGuardHome
Go
Introduced 0 Fixed 0.107.73
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/AdguardTeam/AdGuardHome | 0 | 0.107.73 |
Remediation
No remediation recorded yet.
References (3)
- https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-5fg6-wrq4-w5gh x_refsource_CONFIRMExploitMitigationVendor Advisory
- https://github.com/advisories/GHSA-5fg6-wrq4-w5gh Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32136
| Link | Providers | Tags |
|---|---|---|
| https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-5fg6-wrq4-w5gh | x_refsource_CONFIRMExploitMitigationVendor Advisory | |
| https://github.com/advisories/GHSA-5fg6-wrq4-w5gh | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32136 |
Change history (0)
No recorded changes yet.