{"id":"CVE-2021-29441","aliases":["CVE-2021-29442","GHSA-36hp-jr8h-556f","GHSA-xv5h-v7jh-p2qh"],"url":"https://o3.security/vulnerability/CVE-2021-29441","summary":"Authentication Bypass","details":"Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.","published":"2021-04-27T21:15:07.993Z","modified":"2026-07-09T12:33:12.090903Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[{"ecosystem":"Maven","name":"com.alibaba.nacos:nacos-common","fixedVersion":"1.4.1"}],"fix":{"url":"https://github.com/alibaba/nacos/pull/4703","label":"alibaba/nacos#4703"},"references":[{"type":"FIX","url":"https://github.com/alibaba/nacos/pull/4703"},{"type":"EVIDENCE","url":"https://github.com/advisories/GHSA-36hp-jr8h-556f"},{"type":"EVIDENCE","url":"https://github.com/alibaba/nacos/issues/4701"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:33:12.090903Z"}}