Vulnerability in Warpgate's HTTP Proxy for Linux Affects User Authorization
CVE-2026-63329

4.9MEDIUM

Key Information:

Vendor

Warp-tech

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-63329?

A vulnerability exists in Warpgate, an open-source bastion host for SSH, HTTPS, and MySQL, whereby the application improperly handles the x-warpgate-username header. In versions prior to 0.25.6, a crafted client request can lead to an authenticated attacker being authorized as another user due to the incorrect forwarding of this header. The issue arises when the backend system trusts the initial value of the x-warpgate-username header, potentially compromising user authentication and authorization protocols. The flaw is rectified in version 0.25.6.

Affected Version(s)

warpgate < 0.25.6

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.