
CVE-2026-40910 frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of acces… https://www.cve.org/CVERecord?id=CVE-2026-40910
Post summary
CVE-2026-40910 highlights an authentication bypass in frp’s HTTP vhost routing when routeByHTTPUser is used; no patches, exploits, or active exploitation details are provided.
