VYPR
Medium severity5.3NVD Advisory· Published May 7, 2026· Updated May 13, 2026

CVE-2026-39825

CVE-2026-39825

Description

ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query "a1=x&a2=x&...&a10000=x&hidden=y" can forward the parameter "hidden=y" while hiding it from the proxy's Rewrite function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3289

Patches

Vulnerability mechanics

References

4

News mentions

1