{"id":"GO-2026-5889","summary":"Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour","details":"Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour","aliases":["BIT-contour-2026-50149","CVE-2026-50149","GHSA-g3xr-5w5j-w4q4"],"modified":"2026-08-26T01:11:36.175948748Z","published":"2026-07-07T15:26:37Z","related":["CGA-5q9r-44pm-g2q2"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5889","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/projectcontour/contour/security/advisories/GHSA-g3xr-5w5j-w4q4"}],"affected":[{"package":{"name":"github.com/projectcontour/contour","ecosystem":"Go","purl":"pkg:golang/github.com/projectcontour/contour"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.23.0"},{"fixed":"1.33.5"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5889.json"}}],"schema_version":"1.9.0"}