Centrifugal Centrifugo vulnerabilities
4 known vulnerabilities affecting centrifugal/centrifugo.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-32301P3CRITICALCVSS 9.3fixed in 6.7.02026-03-13
CVE-2026-32301 [CRITICAL] CWE-918 CVE-2026-32301: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vuln
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthenticated attacker can craft a JWT with a malicious iss or aud claim value that gets interpolated into
nvd
CVE-2026-71485P3CRITICALCVSS 9.1fixed in 6.9.02026-08-20
CVE-2026-71485 [CRITICAL] CWE-290 CVE-2026-71485: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in
nvd
CVE-2026-62963P3HIGHCVSS 8.7fixed in 6.8.42026-07-16
CVE-2026-62963 [HIGH] CWE-409 CVE-2026-62963: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidire
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in internal/websocket/conn.go advanceFrame, but ReadMessage used io.ReadAll after decompression without an
nvd
CVE-2026-49998P3HIGHCVSS 8.2fixed in 6.8.12026-07-16
CVE-2026-49998 [HIGH] CWE-347 CVE-2026-49998: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight lookup were keyed only by JWT header kid, not by the resolved JWKS endpoint, issuer, audience, or tru
nvd