CVE-2026-91143

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.

Scoring

Severity
MEDIUM
CVSS base score
7.2
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
EPSS probability
0.27%
CWE
CWE-288
Published
2026-09-14
Last modified
2026-09-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs