centrifugal has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 8.6 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Products
- github.com/centrifugal/centrifugo 1
- github.com/centrifugal/centrifugo/v6 1
2
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
centrifugal vulnerabilities
CVEs affecting centrifugal, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-71485Critical· 9.1Centrifugo is an open-source scalable real-time messaging server
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…
▾ Midnightcentrifugal · github.com/centrifugal/centrifugoEPSS 0.42%via NVD
CVE-2026-49998High· 8.2Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
▾ Twilightcentrifugal · github.com/centrifugal/centrifugo/v6EPSS 0.27%via GHSA