mediumCVSS 6.5Vulnerability

CVE-2026-50149

### Impact When an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.virtualhost.jwtProviders`, Contour does not reject the configuration. Consequently, requests from clients that do not send TLS SNI or send an unrecognized SNI (one that does not match any `HTTPProxy` FQDN) bypass configured JWT verification and are proxied to upstream services without a valid token. To list all `HTTPProxies` with this invalid configuration, run ```bash kubectl get httpproxies -A -o json | jq -r ' .items[] | select(.spec.virtualhost | .tls.enableFallbackCertificate and .jwtProviders) | "Invalid HTTPProxy found: \(.metadata.namespace)/\(.metadata.name)" ' ``` ### Patches This issue is fixed in Contour v1.33.5. Contour now rejects and marks invalid any `HTTPProxy` resources that combine `.spec.virtualhost.tls.enableFallbackCertificate: true` with `.spec.virtualhost.jwtProviders`. Affected resources will receive a status condition with the error reason `TLSIncompatibleFeatures`. ### Workarounds Do not enable `.spec.virtualhost.tls.enableFallbackCertificate` on `HTTPProxy` resources that also define `.spec.virtualhost.jwtProviders`. Remove one of the two settings to avoid the invalid configuration. ### References - Contour fallback certificate documentation: https://projectcontour.io/docs/main/config/tls-termination/#fallback-certificate - Contour JWT verification documentation: https://projectcontour.io/docs/main/config/jwt-verification/

Properties

ghsa_id
GHSA-g3xr-5w5j-w4q4
severity
medium
summary
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
cvss_score
6.5
cve_id
CVE-2026-50149
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-07-02T17:15:20Z
source_url
https://github.com/advisories/GHSA-g3xr-5w5j-w4q4
ghsa_updated
2026-07-02T17:15:23Z

Related Entities (4)

AFFECTS (1)

[Software]go/github.com/projectcontour/contour

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/projectcontour/contour

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-50149 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal