—
GO-2026-4286
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
Quick fix
GO-2026-4286 — github.com/openflagr/flagr: upgrade to the fixed version with the command below.
go get github.com/openflagr/flagr@v0.0.0-20251009103504-fe83dc87aa40Details
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware in github.com/openflagr/flagr
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/openflagr/flagr
Introduced in:
0Fixed in: 0.0.0-20251009103504-fe83dc87aa40Fix
go get github.com/openflagr/flagr@v0.0.0-20251009103504-fe83dc87aa40References
- https://github.com/advisories/GHSA-rwp9-5g7q-73q3[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-0650[ADVISORY]
- https://github.com/openflagr/flagr/commit/fe83dc87aa404a57554aa5839ac450f55c203570[FIX]
- https://dreyand.rs/code%20review/golang/2026/01/03/0day-speedrun-openflagr-less-1118-authentication-bypass[WEB]
- https://github.com/openflagr/flagr/releases/tag/1.1.19[WEB]
- https://www.vulncheck.com/advisories/openflagr-authentication-bypass-via-prefix-whitelist-path-normalization[WEB]