CVE-2026-108899 | tobychui zoraxy up to 3.3.4 Path Exception Matcher authProviders.go handleBasicAuth PathPrefix improper authorization

SecurityVulns

A vulnerability was found in tobychui zoraxy up to 3.3.4. It has been rated as critical. This impacts the function handleBasicAuth of the file mod/dynamicproxy/authProviders.go of the component Path Exception Matcher. This manipulation of the argument PathPrefix causes improper authorization.

The identification of this vulnerability is CVE-2026-108899. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More