{"apiVersion":"1.0","identifier":"CVE-2026-71485","description":"Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in internal/unigrpc/grpc.go can forward an allowlisted value as a trusted backend header or metadata value. A remote client can spoof a header such as x-trusted-user for connect, refresh, subscribe, publish, RPC, and related proxy calls when the backend relies on that header for authentication or authorization. The unidirectional gRPC transport has no transport-level HTTP header that can override the emulated value. This issue is fixed in version 6.9.0.","publishedAt":"2026-08-20T21:17:08","lastModifiedAt":"2026-08-25T16:17:25","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71485","cvssScore":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.00423,"riskScore":0.94,"affectedProduct":"Centrifugo","affectedVersions":"<6.9.0","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-71485","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-71485","en":"https://www.redsauce.net/en/cves/CVE-2026-71485","fr":"https://www.redsauce.net/fr/cves/CVE-2026-71485","pt":"https://www.redsauce.net/pt/cves/CVE-2026-71485","de":"https://www.redsauce.net/de/cves/CVE-2026-71485","sk":"https://www.redsauce.net/sk/cves/CVE-2026-71485","el":"https://www.redsauce.net/el/cves/CVE-2026-71485"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-71485"}}