Skip to main content
EPSS 0.6%top 53%

CVE-2026-71485: CWE-290: Authentication Bypass by Spoofing in centrifugal centrifugo

0
Critical
Published: 09/02/2026 (09/02/2026, 23:41:37 UTC)
Source: CVE Database V5
Vendor/Project: centrifugal
Product: centrifugo

Description

CVE-2026-71485 is an authentication bypass vulnerability in centrifugal centrifugo before version 6.9.0. It arises because client-supplied headers in the connect request are forwarded to backend services without proper validation, allowing attackers to spoof trusted headers used for authentication and authorization. This can lead to full impersonation of any identity the backend trusts based on these headers. The issue affects all proxy call types and persists for the lifetime of the connection.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

centrifugal

centrifugo

Affected versions
<6.9.0
GitHub Actionsmore threats →ai
centrifugal/centrifugo
pkg:github/centrifugal/centrifugo
Affected versions
<6.9.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 23:01:51 UTC

Technical Analysis

The vulnerability occurs because centrifugal centrifugo's proxy configuration options `http_headers` and `grpc_metadata` forward headers from the client's connect request message rather than from genuine transport-level HTTP headers. Operators typically configure these options to forward trusted headers set by reverse proxies or API gateways. However, the client can supply arbitrary header values in the connect request, which centrifugo copies verbatim into an emulated headers context. These client-controlled headers are forwarded to backend services unless overridden by genuine HTTP headers, which do not exist for the unidirectional gRPC transport. This allows attackers to spoof any header the backend trusts for authentication or authorization, enabling full identity impersonation without credentials. The issue was confirmed in centrifugo version 6.8.3 and affects all versions prior to 6.9.0.

Potential Impact

Attackers can fully spoof any header trusted by the backend for authentication or authorization, leading to potential full account or identity impersonation. This bypass requires no credentials, JWTs, or API keys and affects all proxy call types for the entire connection lifetime. The backend may grant unauthorized access or privileges based on the spoofed headers.

Mitigation Recommendations

No official patch or fix is currently documented. Operators should be aware that `http_headers` and `grpc_metadata` proxy options can be supplied by clients and are not guaranteed to originate from trusted reverse proxies. It is recommended to avoid relying on client-supplied headers for authentication or authorization decisions. The vendor suggests documenting this behavior explicitly and providing a separate allowlist for headers sourced only from genuine transport-level HTTP headers. For the unidirectional gRPC transport, consider disabling `http_headers` forwarding entirely. Monitor the vendor advisory for updates and official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-08-06T19:56:23.725Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a876c9aacd9273b4920bdfe

Added to database: 08/20/2026, 21:07:38 UTC

Last enriched: 09/10/2026, 23:01:51 UTC

Last updated: 10/05/2026, 06:48:18 UTC

Views: 83

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses