CVE-2026-71485: Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
(updated )
Full spoofing of any header value the backend trusts for authentication/authorization, for every proxy call type, for the lifetime of the connection – up to full account/identity impersonation depending on backend logic. No credentials, JWT, or API key required.
References
- github.com/advisories/GHSA-9468-v6mj-fppw
- github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0
- github.com/centrifugal/centrifugo/pull/1182
- github.com/centrifugal/centrifugo/releases/tag/v6.9.0
- github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw
- nvd.nist.gov/vuln/detail/CVE-2026-71485
Code Behaviors & Features
Detect and mitigate CVE-2026-71485 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →