Executive brief
Isaiah, a web-based tool for managing Docker container fleets, contains a security flaw in how it verifies user identity when used with a reverse proxy. If the application is not strictly isolated, an attacker can bypass the login screen by providing a fake authentication header in their request. This could allow an unauthorized user to view sensitive container data, access logs, and perform administrative Docker management operations.
Technical details
A vulnerability in will-moss Isaiah up to 1.36.9 involves improper authentication (CWE-287) within the WebSocket connection handler in `app/main.go`. When `FORWARD_PROXY_AUTHENTICATION_ENABLED` is active, the application trusts the identity provided in HTTP headers (e.g., `Remote-User`) without verifying if the request originated from a trusted proxy. An attacker with network access to the Isaiah backend can bypass the authentication flow by manually supplying the configured header during the `/ws` WebSocket handshake. A pull request (#36) has been submitted to introduce a `FORWARD_PROXY_AUTHENTICATION_TRUSTED_PROXIES` IP/CIDR allowlist to mitigate this issue.
Affected products
- will-moss Isaiah up to 1.36.9
Timeline
- 2026-06-10: disclosed: Issue and fix pull request opened on GitHub
- 2026-07-13: advisory: CVE published to NVD dataset