Vulnerability GO-2026-6490
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 hours ago
September 28, 2026 at 04:43 PM UTC
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo
v0.1.0 - v2.4.0+incompatible
v0.1.0 - v2.4.0+incompatible
Summary
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo
Details
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
25 days ago
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
v0.1.0 - v2.4.0+incompatible GHSA-9468-v6mj-fppw
v0.1.0 - v2.4.0+incompatible GHSA-9468-v6mj-fppw
Unknown
2 months ago
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass in github.com/centrifugal/centrifugo
v5.0.0 - v5.4.9 GO-2026-5872
v5.0.0 - v5.4.9 GO-2026-5872
Unknown
2 months ago
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass in github.com/centrifugal/centrifugo
v5.0.0 - v5.4.9 GO-2026-5872
v5.0.0 - v5.4.9 GO-2026-5872
Unknown
2 months ago
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass in github.com/centrifugal/centrifugo
v5.0.0 - v5.4.9 GO-2026-5872
v5.0.0 - v5.4.9 GO-2026-5872
Unknown
2 months ago
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass in github.com/centrifugal/centrifugo
v5.0.0 - v5.4.9 GO-2026-5872
v5.0.0 - v5.4.9 GO-2026-5872
Impacted packages
Timeline
Published
3 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:00 PM UTC