CVE-2026-63405 | AnyCable up to 1.6.14 Pusher-compatible REST API pusher/http.go handleEvents body_md5 data authenticity

SecurityVulns

A vulnerability was found in AnyCable up to 1.6.14. It has been declared as problematic. The affected element is the function handleEvents of the file pusher/http.go of the component Pusher-compatible REST API. Executing a manipulation of the argument body_md5 can lead to insufficient verification of data authenticity.

The identification of this vulnerability is CVE-2026-63405. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More