CVE-2026-40910
קריטית 9.1
תיאור (מקור, אנגלית)
frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style requests, the routing logic uses the username from Proxy-Authorization to select the routeByHTTPUser backend, while the access control check uses credentials from the regular Authorization header. As a result, an attacker who can reach the HTTP vhost entrypoint and knows or can guess the protected routeByHTTPUser value may access a backend protected by httpUser / httpPassword even with an incorrect Proxy-Authorization password. This issue affects deployments that explicitly use routeByHTTPUser. It does not affect ordinary HTTP proxies that do not use this feature. This vulnerability is fixed in 0.68.1.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-29/7/2026
- CWE
- CWE-287
מוצרים מושפעים
fatedier: frp
קישורים
- https://github.com/fatedier/frp/security/advisories/GHSA-pq96-pwvg-vrr9 ExploitVendor Advisory
- https://github.com/fatedier/frp/security/advisories/GHSA-pq96-pwvg-vrr9 ExploitVendor Advisory