Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2rx5-2g7j-2659 | Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel |
Tue, 15 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Azukaar
Azukaar cosmos-server |
|
| Vendors & Products |
Azukaar
Azukaar cosmos-server |
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19. | |
| Title | Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server | |
| Weaknesses | CWE-285 CWE-290 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T14:50:54.216Z
Reserved: 2026-05-30T02:43:33.106Z
Link: CVE-2026-49446
Updated: 2026-09-15T14:50:50.514Z
Status : Received
Published: 2026-09-15T15:17:16.747
Modified: 2026-09-15T15:17:16.747
Link: CVE-2026-49446
No data.
OpenCVE Enrichment
Updated: 2026-09-15T15:30:15Z
Github GHSA