GHSA-rwp9-5g7q-73q3

Suggest an improvement
Source
https://github.com/advisories/GHSA-rwp9-5g7q-73q3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rwp9-5g7q-73q3/GHSA-rwp9-5g7q-73q3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rwp9-5g7q-73q3
Aliases
Published
2026-01-07T12:31:25Z
Modified
2026-02-03T03:16:23Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware
Details

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and access protected API endpoints without valid credentials. Unauthorized access may allow modification of feature flags and export of sensitive data.

Database specific
{
    "cwe_ids":  [
        "CWE-306",
        "CWE-425"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-07T19:31:31Z",
    "nvd_published_at":  "2026-01-07T12:17:07Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Go / github.com/openflagr/flagr

Package

Name
github.com/openflagr/flagr
View open source insights on deps.dev
Purl
pkg:golang/github.com/openflagr/flagr

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20251009103504-fe83dc87aa40

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-rwp9-5g7q-73q3/GHSA-rwp9-5g7q-73q3.json"