github.com/centrifugal/centrifugo vulnerabilities
CVEs whose affected-version data names the github.com/centrifugal/centrifugo package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-71485Critical· 9.1Centrifugo is an open-source scalable real-time messaging server
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…
▾ Midnightcentrifugal · github.com/centrifugal/centrifugoEPSS 0.42%via NVD
CVE-2026-49998High· 8.2Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
▾ Twilightcentrifugal · github.com/centrifugal/centrifugo/v6EPSS 0.27%via GHSA