CVE-2026-71485 | Centrifugal Centrifugo up to 6.8.x Connection handler.go OnClientConnecting headers improper authorization
A vulnerability identified as critical has been detected in Centrifugal Centrifugo up to 6.8.x. Impacted is the function OnClientConnecting of the file internal/client/handler.go of the component Connection Handler. This manipulation of the argument headers causes improper authorization.
This vulnerability is handled as CVE-2026-71485. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More