Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-50149 1 Projectcontour 1 Contour 2026-07-15 6.5 Medium
A flaw was found in Contour. When an HTTPProxy is configured with both a fallback certificate and JWT (JSON Web Token) providers, Contour does not properly enforce JWT verification. This allows remote attackers to bypass security checks by sending requests without a valid token, specifically when clients do not provide a TLS Server Name Indication (SNI) or provide an unrecognized SNI. The consequence is unauthorized access to upstream services and potential information disclosure.