CVE-2026-58399Critical▾ Midnight@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.5%
0.5% → 1.0%
@acastellon/auth v2.2.0 appears to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers.
The validateToken middleware contains a service-to-service bypass for auth-user: service-brother when req.get('host').startsWith(getHostName()). Both values involved in the check can be influenced by an unauthenticated HTTP client: auth-user is a request header, and Host is also client-controlled. As a result, a remote unauthenticated attacker can send a request with crafted headers and bypass token validation before the normal legacy/JWT/OIDC validation logic runs.
Impact: An attacker may be able to access routes protected by validateToken() without a valid token. In deployments where downstream services trust auth-user or is-* headers, this may also lead to privilege escalation.
Affected package: @acastellon/auth v2.2.0
Affected code: auth.js, validateToken() The issue is related to the service-brother bypass and getHostName() check.
Example request:
GET /protected HTTP/1.1
Host: <configured CNAME or hostname>
auth-user: service-brother
is-admin: true
Expected behavior: The request should require a valid authentication token.
Actual behavior: The middleware calls next() before token validation.
Fix implemented in v2.3.0+:
Removed the spoofable bypass. Always sanitize incoming auth-user and is-* headers. Added mTLS client certificate based service auth (with optional TRUSTED_MTLS_SERVICES allowlist). Updated consumers (rest, graphql, dns-client) for mTLS support. Unit tests added for sanitization + mTLS path.
@acastellon/auth < 2.3.0Upgrade to a patched release:
@acastellon/auth 2.3.0Connected by shared product, vendor, weakness, or advisory.
GHSA-gfj5-979r-92pwCritical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
CVE-2026-56675High· 8.39router /v1 APIs has unauthenticated access via reverse proxy locality collapse
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-48063CriticalBaileys is a cocket-based TS/JavaScript API for WhatsApp Web
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVE-2026-49353High· 7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING