github.com/centrifugal/centrifugo
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/centrifugal/centrifugopage 1 of 1
- CVE-2026-32301CRITICALCVSS 9.3EG 9.32026-03-13
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). A…
- CVE-2026-49998HIGHCVSS 8.2EG 8.22026-07-01
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and …
- CVE-2026-71485CRITICALCVSS 9.1EG 9.1✓ Fixed in 6.9.02026-08-20
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, a…
Check whether github.com/centrifugal/centrifugo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/centrifugal/centrifugo CVEs against the assets you own.
Start Free Scan →