Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

redhat логотип

CVE-2026-50149

около 1 месяца назад

A flaw was found in Contour. When an HTTPProxy is configured with both a fallback certificate and JWT (JSON Web Token) providers, Contour does not properly enforce JWT verification. This allows remote attackers to bypass security checks by sending requests without a valid token, specifically when clients do not provide a TLS Server Name Indication (SNI) or provide an unrecognized SNI. The consequence is unauthorized access to upstream services and potential information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g3xr-5w5j-w4q4

около 1 месяца назад

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-50149

A flaw was found in Contour. When an HTTPProxy is configured with both a fallback certificate and JWT (JSON Web Token) providers, Contour does not properly enforce JWT verification. This allows remote attackers to bypass security checks by sending requests without a valid token, specifically when clients do not provide a TLS Server Name Indication (SNI) or provide an unrecognized SNI. The consequence is unauthorized access to upstream services and potential information disclosure.

CVSS3: 6.5
около 1 месяца назад
github логотип
GHSA-g3xr-5w5j-w4q4

Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled

CVSS3: 6.5
около 1 месяца назад

Уязвимостей на страницу