HIGH
bablilayoub
CVE published 2026-07-28
CVE-2026-54650
CVE-2026-54650 is a high-severity vulnerability in openhole that allows path traversal attacks by forwarding r.URL.Path instead of preserving the original request target. This issue is fixed in version 0.1.2. The vulnerability arises from openhole-server in internal/server/public_proxy.go not properly handling URL paths, allowing percent-encoded dot segments and separators to reach tunneled local services [truncated]