7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/centrifugal/centrifugo/v5 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-49998
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
UNKNOWN
CVE-2026-49998
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass in github.com/centrifugal/centrifugo
CRITICAL 9.3
CVE-2026-32301
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL
NONE 0.0
GO-2026-4703
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning
UNKNOWN
GHSA-q926-c743-49qj
Centrifugo's InsecureSkipTokenSignatureVerify flag silently disables JWT verification with no warning in github.com/centrifugal/centrifugo
UNKNOWN
CVE-2026-32301
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL in github.com/centrifugal/centrifugo
UNKNOWN
GHSA-j9wf-6r2x-hqmx
Centrifugo v6.6.0 dependency vulnerabilities in github.com/centrifugal/centrifugo
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes