MEDIUM
snail007
CVE published 2026-09-14
CVE-2026-91143
CVE-2026-91143 debrief: goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements and potentially enabling arbitrary TCP traffic relay and access to restricted destinations. This issue affects proxy configurations and authentication measures, requiring defenders to assess exposure and apply necessary u [truncated]