CVE-2026-71485
- EPSS -
- Veröffentlicht 20.08.2026 21:01:00
- Zuletzt bearbeitet 20.08.2026 21:17:08
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmula...
CVE-2026-62963
- EPSS 0.3%
- Veröffentlicht 16.07.2026 19:34:48
- Zuletzt bearbeitet 17.07.2026 18:44:13
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in i...
CVE-2026-49998
- EPSS 0.18%
- Veröffentlicht 16.07.2026 19:33:33
- Zuletzt bearbeitet 17.07.2026 18:42:17
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singlefligh...
CVE-2026-32301
- EPSS 0.26%
- Veröffentlicht 12.03.2026 21:19:03
- Zuletzt bearbeitet 18.03.2026 18:02:29
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthent...