@acastellon/auth vulnerabilities
CVEs whose affected-version data names the @acastellon/auth package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-58399Critical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
▾ Midnightacastellon · @acastellon/authEPSS 0.97%via GHSA
GHSA-gfj5-979r-92pwCritical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
▾ Midnightacastellon · @acastellon/authvia GHSA