Vulnerability GO-2026-6516
Summary
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go
Details
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body in github.com/anycable/anycable-go.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/anycable/anycable-go before v1.6.15.
Related Vulnerabilities
Other vulnerabilities affecting the same packages