CVE-2026-71485: CWE-290: Authentication Bypass by Spoofing in centrifugal centrifugo
Description
CVE-2026-71485 is an authentication bypass vulnerability in centrifugal centrifugo before version 6.9.0. It arises because client-supplied headers in the connect request are forwarded to backend services without proper validation, allowing attackers to spoof trusted headers used for authentication and authorization. This can lead to full impersonation of any identity the backend trusts based on these headers. The issue affects all proxy call types and persists for the lifetime of the connection.
CVSS v3.1
Score 9.1critical
Affected software
centrifugal
centrifugo
pkg:github/centrifugal/centrifugoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability occurs because centrifugal centrifugo's proxy configuration options `http_headers` and `grpc_metadata` forward headers from the client's connect request message rather than from genuine transport-level HTTP headers. Operators typically configure these options to forward trusted headers set by reverse proxies or API gateways. However, the client can supply arbitrary header values in the connect request, which centrifugo copies verbatim into an emulated headers context. These client-controlled headers are forwarded to backend services unless overridden by genuine HTTP headers, which do not exist for the unidirectional gRPC transport. This allows attackers to spoof any header the backend trusts for authentication or authorization, enabling full identity impersonation without credentials. The issue was confirmed in centrifugo version 6.8.3 and affects all versions prior to 6.9.0.
Potential Impact
Attackers can fully spoof any header trusted by the backend for authentication or authorization, leading to potential full account or identity impersonation. This bypass requires no credentials, JWTs, or API keys and affects all proxy call types for the entire connection lifetime. The backend may grant unauthorized access or privileges based on the spoofed headers.
Mitigation Recommendations
No official patch or fix is currently documented. Operators should be aware that `http_headers` and `grpc_metadata` proxy options can be supplied by clients and are not guaranteed to originate from trusted reverse proxies. It is recommended to avoid relying on client-supplied headers for authentication or authorization decisions. The vendor suggests documenting this behavior explicitly and providing a separate allowlist for headers sourced only from genuine transport-level HTTP headers. For the unidirectional gRPC transport, consider disabling `http_headers` forwarding entirely. Monitor the vendor advisory for updates and official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-06T19:56:23.725Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a876c9aacd9273b4920bdfe
Added to database: 08/20/2026, 21:07:38 UTC
Last enriched: 09/10/2026, 23:01:51 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 83
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.