<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 04:13:45 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368634</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368634</link>
      <description>EUVD-2026-368634</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368634</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49446</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49446</link>
      <description>&lt;p&gt;Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49446</guid>
    </item>
    <item>
      <title>GHSA-2rx5-2g7j-2659 — Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2rx5-2g7j-2659</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/azukaar/cosmos-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request&amp;#39;s `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and before the `AdminOnlyWithRedirect` gate at lines 109-117 runs. Any holder of a valid Constellation device API key sends `x-cosmos-user: admin` to a proxied backend; the documented forward-auth integration treats the caller as admin with no JWT cookie, password, or MFA.&lt;/p&gt;
&lt;p&gt;### Preconditions&lt;/p&gt;
&lt;p&gt;- Cosmos is deployed with Constellation enabled and at least one device enrolled.
- Attacker holds a valid `x-cstln-auth` API key for an enrolled device.
- Attacker reaches Cosmos over the Constellation Nebula tunnel.
- Target proxy route has `AuthEnabled=true`; upstream trusts the `x-cosmos-user` forward-auth header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// src/proxy/routerGen.go:46-122 - bypass returns before headers are reset
func tokenMiddleware(route utils.ProxyRouteConfig) func(next http.Handler) http.Handler {
    return func(next http.Handler) http.Handler {
        return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
            enabled := route.AuthEnabled
            adminOnly := route.AdminOnly&lt;/p&gt;
&lt;p&gt;// bypass auth if from Constellation tunnel
            if ((enabled &amp;amp;&amp;amp; r.Header.Get(&amp;#34;x-cosmos-user&amp;#34;) != &amp;#34;&amp;#34;) || !enabled) {  // attacker-set header opens the branch
                remoteAddr, _ := utils.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/azukaar/cosmos-server&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request&amp;#39;s `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and before the `AdminOnlyWithRedirect` gate at lines 109-117 runs. Any holder of a valid Constellation device API key sends `x-cosmos-user: admin` to a proxied backend; the documented forward-auth integration treats the caller as admin with no JWT cookie, password, or MFA.&lt;/p&gt;
&lt;p&gt;### Preconditions&lt;/p&gt;
&lt;p&gt;- Cosmos is deployed with Constellation enabled and at least one device enrolled.
- Attacker holds a valid `x-cstln-auth` API key for an enrolled device.
- Attacker reaches Cosmos over the Constellation Nebula tunnel.
- Target proxy route has `AuthEnabled=true`; upstream trusts the `x-cosmos-user` forward-auth header.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;```go
// src/proxy/routerGen.go:46-122 - bypass returns before headers are reset
func tokenMiddleware(route utils.ProxyRouteConfig) func(next http.Handler) http.Handler {
    return func(next http.Handler) http.Handler {
        return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
            enabled := route.AuthEnabled
            adminOnly := route.AdminOnly&lt;/p&gt;
&lt;p&gt;// bypass auth if from Constellation tunnel
            if ((enabled &amp;amp;&amp;amp; r.Header.Get(&amp;#34;x-cosmos-user&amp;#34;) != &amp;#34;&amp;#34;) || !enabled) {  // attacker-set header opens the branch
                remoteAddr, _ := utils.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2rx5-2g7j-2659</guid>
    </item>
  </channel>
</rss>
