GO-2026-5969None▾ SunlitTSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy
github.com/almeidapaulopt/tsdproxy < 1.4.4-0.20260603142855-434819b4421eUpgrade to a patched release:
github.com/almeidapaulopt/tsdproxy 1.4.4-0.20260603142855-434819b4421eConnected by shared product, vendor, weakness, or advisory.
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
GO-2026-5982NoneTsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services in github.com/almeidapaulopt/tsdproxy
GHSA-pqg7-v6wh-3pfpHigh· 8.5TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services