Answer in brief
CVE-2026-71485 records a Critical severity (CVSS 9.1) vulnerability in Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends. The current sources do not mark it as known exploited. The current feed maps centrifugal/centrifugo (generic), github.com/centrifugal/centrifugo (go), github.com/centrifugal/centrifugo (go), github.com/centrifugal/centrifugo (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps centrifugal/centrifugo (generic), github.com/centrifugal/centrifugo (go), github.com/centrifugal/centrifugo (go), github.com/centrifugal/centrifugo (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| centrifugal/centrifugogeneric | <6.9.0 | 6.9.0 |
| github.com/centrifugal/centrifugogo | <=6.8.4 | 6.9.0 |
| github.com/centrifugal/centrifugogo | >=0 <6.9.0 | 6.9.0 |
| github.com/centrifugal/centrifugogo | >=0 | Not reported |
| github.com/centrifugal/centrifugo/v3go | >=0 | Not reported |
| github.com/centrifugal/centrifugo/v4go | >=0 | Not reported |
| github.com/centrifugal/centrifugo/v5go | >=0 | Not reported |
| github.com/centrifugal/centrifugo/v6go | >=0 <6.9.0 | 6.9.0 |
Published upstream
Aug 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 20, 2026
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in internal/unigrpc/grpc.go can forward an allowlisted value as a trusted backend header or metadata value. A remote client can spoof a header such as x-trusted-user for connect, refresh, subscribe, publish, RPC, and related proxy calls when the backend relies on that header for authentication or authorization. The unidirectional gRPC transport has no transport-level HTTP header that can override the emulated value. This issue is fixed in version 6.9.0.
Quoted source text, attributed separately from HOL analysis.