Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49446— Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server

Quick assessment

Affected
azukaar Cosmos-Server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cosmos 允许用户自行托管一个主服务器,它既可以作为应用程序的安全网关,也可以作为服务器管理器。 在 0.22.19 版本之前,位于 中的 在移除 、 、 和 请求头以及调用 之前,就会通过 Constellation 隧道返回。 对于拥有已注册设备的有效 API 密钥的攻击者,如果通过 Constellation Nebula 隧道访问 Cosmos,并且上游应用信任这些转发认证请求头,攻击者可以向启用了 的路由提供自选的 值。 这样,请求将绕过 Cosmos 的 JWT、密码、多因素认证(MFA)以及 检查

CVSS 6.1 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49446

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server
Source: CVE Program / CVE List V5
Vulnerability Description
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
azukaar Cosmos-Server < 0.22.19 -

II. Public POCs for CVE-2026-49446

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49446

登录查看更多情报信息。

Vendor Advisories for CVE-2026-49446 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49446

No comments yet


Leave a comment