Intel

AIKIDO-2026-502505

nono-proxy is vulnerable to Improper Access Control

Improper Access ControlGHSA-8r33-hr9m-69wh Published 6 days ago

82

High Risk

This Affects:

RUSTnono-proxy
0.42.0 - 0.77.0
Fixed in 0.78.0
Are you affected? Scan for Free

TL;DR

The credential proxy matches endpoint policy against a normalized request path but forwards the raw path to the upstream. Dot segments and ; path parameters survive that normalizer, so an allowlisted prefix can authorize a path the upstream then resolves to a denied endpoint, and the proxy still injects credentials. The fix rejects ambiguous proxy paths after a stricter normalization.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use endpoint policy on the credential proxy.

Background info

nono-proxy is vulnerable to Improper Access Control in versions 0.42.0 - 0.77.0.

How to fix this

Upgrade the nono-proxy library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform