---
id: CVE-2026-86242
title: >-
  Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose
  path is an HTTP URL through unauthenticated POST /api/plugins when management
  authentication is disabled (the default,
  governance.auth_config.is_enabled=false)
summary: >-
  Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose
  path is an HTTP URL through unauthenticated POST /api/plugins when management
  authentication is disabled (the default,
  governance.auth_config.is_enabled=false). T…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-284
  - CWE-306
vendor: maximhq
product: github.com/maximhq/bifrost/transports
affected:
  - github.com/maximhq/bifrost/transports < 2.0.0
published: '2026-09-06'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:44:01.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86242'
references:
  - url: 'https://github.com/maximhq/bifrost'
    label: reefs@jfrog.com
  - url: >-
      https://github.com/maximhq/bifrost/commit/e0057ff355f831c251eabe9d0e44f3a3748532c6
    label: reefs@jfrog.com
  - url: 'https://github.com/maximhq/bifrost/pull/5763'
    label: reefs@jfrog.com
  - url: 'https://github.com/maximhq/bifrost/releases/tag/transports/v2.0.0'
    label: reefs@jfrog.com
  - url: 'https://github.com/maximhq/bifrost/security/advisories/GHSA-2qp8-4xgm-fw6g'
    label: reefs@jfrog.com
tags:
  - nvd
  - cve.org
epss: 0.01064
epssPercentile: 0.63146
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T18:23:19.631126Z'
ingestedAt: '2026-09-07T03:04:07.532Z'
---

## Overview

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful open, optional Init runs immediately with the supplied config as the Bifrost process user. On documented dynamically linked builds (DYNAMIC=1 / no static-link flags), which the vendor requires for custom Go plugins, plugin.Open is expected to succeed and this is unauthenticated remote code execution. On the published statically linked Docker image, plugin.Open fails with Dynamic loading not supported, so that build class is only server-side request forgery. Attack complexity is High because the attacker cannot force RCE on the default static image and a loadable plugin must match the host Go version, OS, architecture, and linkage. The 1.6.x HTTP transport line through 1.6.11 does not contain the fix.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
