github.com/fatedier/frp
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/fatedier/frppage 1 of 1
- CVE-2026-40910MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.68.12026-04-21
frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style requests, the routing logic uses the username f…
- CVE-2026-73564HIGHCVSS 8.7EG 8.7✓ Fixed in 0.70.12026-08-13
frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF make…
Check whether github.com/fatedier/frp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/fatedier/frp CVEs against the assets you own.
Start Free Scan →