---
id: GO-2026-5969
aliases:
  - GHSA-g936-7jqj-mwv8
title: >-
  TSDProxy: Internal proxy auth token forwarded to backend services enables
  management API escalation in github.com/almeidapaulopt/tsdproxy
summary: >-
  TSDProxy: Internal proxy auth token forwarded to backend services enables
  management API escalation in github.com/almeidapaulopt/tsdproxy
severity: none
vendor: almeidapaulopt
product: github.com/almeidapaulopt/tsdproxy
ecosystem: go
affected:
  - github.com/almeidapaulopt/tsdproxy < 1.4.4-0.20260603142855-434819b4421e
patched:
  - github.com/almeidapaulopt/tsdproxy 1.4.4-0.20260603142855-434819b4421e
published: '2026-07-17'
updated: '2026-07-21'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2026-5969'
references:
  - url: >-
      https://github.com/almeidapaulopt/tsdproxy/security/advisories/GHSA-g936-7jqj-mwv8
tags:
  - osv
  - go
ingestedAt: '2026-07-22T15:33:23.684Z'
---

## Overview

TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation in github.com/almeidapaulopt/tsdproxy

## Affected packages

- `github.com/almeidapaulopt/tsdproxy < 1.4.4-0.20260603142855-434819b4421e`

## Remediation

Upgrade to a patched release:

- `github.com/almeidapaulopt/tsdproxy 1.4.4-0.20260603142855-434819b4421e`
