Centrifugal

Centrifugo

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 21:01:00
  • Zuletzt bearbeitet 20.08.2026 21:17:08

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmula...

  • EPSS 0.3%
  • Veröffentlicht 16.07.2026 19:34:48
  • Zuletzt bearbeitet 17.07.2026 18:44:13

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in i...

  • EPSS 0.18%
  • Veröffentlicht 16.07.2026 19:33:33
  • Zuletzt bearbeitet 17.07.2026 18:42:17

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singlefligh...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 12.03.2026 21:19:03
  • Zuletzt bearbeitet 18.03.2026 18:02:29

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthent...