cbcvebase.

Centrifugal Centrifugo vulnerabilities

4 known vulnerabilities affecting centrifugal/centrifugo.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-32301P3CRITICALCVSS 9.3fixed in 6.7.02026-03-13
CVE-2026-32301 [CRITICAL] CWE-918 CVE-2026-32301: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vuln Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthenticated attacker can craft a JWT with a malicious iss or aud claim value that gets interpolated into
nvd
CVE-2026-71485P3CRITICALCVSS 9.1fixed in 6.9.02026-08-20
CVE-2026-71485 [CRITICAL] CWE-290 CVE-2026-71485: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in
nvd
CVE-2026-62963P3HIGHCVSS 8.7fixed in 6.8.42026-07-16
CVE-2026-62963 [HIGH] CWE-409 CVE-2026-62963: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidire Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_websocket.message_size_limit against compressed wire-frame length in internal/websocket/conn.go advanceFrame, but ReadMessage used io.ReadAll after decompression without an
nvd
CVE-2026-49998P3HIGHCVSS 8.2fixed in 6.8.12026-07-16
CVE-2026-49998 [HIGH] CWE-347 CVE-2026-49998: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight lookup were keyed only by JWT header kid, not by the resolved JWKS endpoint, issuer, audience, or tru
nvd
Centrifugal Centrifugo vulnerabilities | cvebase