Improper Authentication in Crow - #VU147366
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and access protected WebSocket functionality.
The vulnerability exists due to improper authentication in the WebSocket upgrade branch of the connection request handler when processing a WebSocket upgrade request rejected by global authentication middleware. A remote attacker can send an unauthenticated WebSocket upgrade request to bypass authentication and access protected WebSocket functionality.