PT-2026-91741 · Goproxy · Goproxy
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
goproxy versions prior to 15.4
Description
The software fails to apply HTTP proxy basic authentication to CONNECT tunnel requests. This allows unauthenticated clients to bypass credential requirements by issuing CONNECT requests to establish tunnels through the authenticated proxy. Consequently, attackers can relay arbitrary TCP traffic and gain access to restricted destinations.
Recommendations
Update to a version newer than 15.3.
Exploit
Fix
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Goproxy