CVE-2026-91143
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-288
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- snail007 goproxy
Weakness type
Related vulnerabilities
- CVE-2026-20079 — Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
- CVE-2026-1603 — An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to
- CVE-2026-18577 — Incomplete patch leads to administrative account takeover
- CVE-2026-18556 — Unauthenticated administrative account takeover
- CVE-2026-28411 — WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`
- CVE-2026-27842 — Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication an
- CVE-2026-33950 — signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
- CVE-2026-34040 — Moby has AuthZ plugin bypass when provided oversized request bodies