goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations. | |
| Title | goproxy through 15.3 Authentication Bypass via CONNECT | |
| First Time appeared |
Goproxy Project
Goproxy Project goproxy |
|
| Weaknesses | CWE-288 | |
| CPEs | cpe:2.3:a:goproxy_project:goproxy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Goproxy Project
Goproxy Project goproxy |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T21:45:43.908Z
Reserved: 2026-09-14T20:35:39.074Z
Link: CVE-2026-91143
No data.
Status : Received
Published: 2026-09-14T22:16:58.880
Modified: 2026-09-14T22:16:58.880
Link: CVE-2026-91143
No data.
OpenCVE Enrichment
No data.
Weaknesses