What is CVE-2026-54650?
CVE-2026-54650 affects the 'openhole' tool. In versions 0.1.1 and earlier, using `r.URL.Path` instead of `r.URL.EscapedPath()` allowed percent-encoded dot segments like `%2e` to bypass restrictions, potentially exposing localhost to the internet. Users should update to the latest version.
Azərbaycanca: CVE-2026-54650 'openhole' alətində aşkarlanıb. 0.1.1 və daha əvvəlki versiyalarda, `r.URL.Path` istifadəsi səbəbindən `%2e` (nöqtə) kimi kodlanmış simvollar vasitəsilə `localhost` ünvanının internetə sızması baş verə bilər. Təsirə məruz qalmamaq üçün alətin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which tool was CVE-2026-54650 discovered, and which versions are affected?
The vulnerability was discovered in the 'openhole' tool. Versions 0.1.1 and earlier are affected.
What measure should be taken to protect against CVE-2026-54650?
To avoid being affected, it is recommended to update the 'openhole' tool to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.