{"id":"GHSA-g3xr-5w5j-w4q4","summary":"Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled","details":"### Impact\n\nWhen an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.virtualhost.jwtProviders`, Contour does not reject the configuration. Consequently, requests from clients that do not send TLS SNI or send an unrecognized SNI (one that does not match any `HTTPProxy` FQDN) bypass configured JWT verification and are proxied to upstream services without a valid token.\n\nTo list all `HTTPProxies` with this invalid configuration, run\n\n```bash\nkubectl get httpproxies -A -o json | jq -r '\n  .items[]\n  | select(.spec.virtualhost | .tls.enableFallbackCertificate and .jwtProviders)\n  | \"Invalid HTTPProxy found: \\(.metadata.namespace)/\\(.metadata.name)\"\n'\n```\n\n### Patches\n\nThis issue is fixed in Contour v1.33.5. Contour now rejects and marks invalid any `HTTPProxy` resources that combine `.spec.virtualhost.tls.enableFallbackCertificate: true` with `.spec.virtualhost.jwtProviders`. Affected resources will receive a status  condition with the error reason `TLSIncompatibleFeatures`.\n\n### Workarounds\n\nDo not enable `.spec.virtualhost.tls.enableFallbackCertificate` on `HTTPProxy` resources that also define `.spec.virtualhost.jwtProviders`. Remove one of the two settings to avoid the invalid configuration.\n\n### References\n\n- Contour fallback certificate documentation: https://projectcontour.io/docs/main/config/tls-termination/#fallback-certificate\n- Contour JWT verification documentation: https://projectcontour.io/docs/main/config/jwt-verification/","aliases":["BIT-contour-2026-50149","CVE-2026-50149","GO-2026-5889"],"modified":"2026-08-25T10:11:16.821552974Z","published":"2026-07-02T17:15:20Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-295"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T17:15:20Z"},"references":[{"type":"WEB","url":"https://github.com/projectcontour/contour/security/advisories/GHSA-g3xr-5w5j-w4q4"},{"type":"PACKAGE","url":"https://github.com/projectcontour/contour"}],"affected":[{"package":{"name":"github.com/projectcontour/contour","ecosystem":"Go","purl":"pkg:golang/github.com/projectcontour/contour"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.23.0"},{"fixed":"1.33.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g3xr-5w5j-w4q4/GHSA-g3xr-5w5j-w4q4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}