VYPR
Critical severity9.8NVD Advisory· Published May 21, 2022· Updated Jun 17, 2026

CVE-2022-31259

CVE-2022-31259

Description

The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/beego/beego/v2Go
< 2.0.32.0.3
github.com/beego/beegoGo
< 1.12.91.12.9

Affected products

4

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.