<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T05:53:24.114222+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368634</id>
    <title>EUVD-2026-368634</title>
    <updated>2026-10-08T05:53:24.160778+00:00</updated>
    <content>EUVD-2026-368634</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368634"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49446</id>
    <title>fkie_cve-2026-49446</title>
    <updated>2026-10-08T05:53:24.160815+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2rx5-2g7j-2659</id>
    <title>GHSA-2rx5-2g7j-2659 — Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel</title>
    <updated>2026-10-08T05:53:24.160851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/azukaar/cosmos-server</p>
<p>### Summary</p>
<p>The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and before the `AdminOnlyWithRedirect` gate at lines 109-117 runs. Any holder of a valid Constellation device API key sends `x-cosmos-user: admin` to a proxied backend; the documented forward-auth integration treats the caller as admin with no JWT cookie, password, or MFA.</p>
<p>### Preconditions</p>
<p>- Cosmos is deployed with Constellation enabled and at least one device enrolled.
- Attacker holds a valid `x-cstln-auth` API key for an enrolled device.
- Attacker reaches Cosmos over the Constellation Nebula tunnel.
- Target proxy route has `AuthEnabled=true`; upstream trusts the `x-cosmos-user` forward-auth header.</p>
<p>### Details</p>
<p>```go
// src/proxy/routerGen.go:46-122 - bypass returns before headers are reset
func tokenMiddleware(route utils.ProxyRouteConfig) func(next http.Handler) http.Handler {
    return func(next http.Handler) http.Handler {
        return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
            enabled := route.AuthEnabled
            adminOnly := route.AdminOnly</p>
<p>// bypass auth if from Constellation tunnel
            if ((enabled &amp;&amp; r.Header.Get("x-cosmos-user") != "") || !enabled) {  // attacker-set header opens the branch
                remoteAddr, _ := utils.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2rx5-2g7j-2659"/>
  </entry>
</feed>
