
Security update: authentication bypass via encoded path traversal is fixed in Bifrost v2.2.5
We fixed an authentication bypass in the Bifrost HTTP gateway. A request that used percent-encoded dot segments, such as ..%2F, could make a protected route look like a public one. The request then skipped authentication. The fix ships in transports/v2.2.5. This affects instances where the gateway can be reached by clients you do not trust. Instances on private networks have much lower exposure, because an attacker first needs access to that network. Because a compromised internal host could st
























