GO-2026-6490
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo
Quick fix
GO-2026-6490 — github.com/centrifugal/centrifugo/v6: upgrade to the fixed version with the command below.
go get github.com/centrifugal/centrifugo/v6@v6.9.0Details
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends in github.com/centrifugal/centrifugo
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/centrifugal/centrifugo (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/centrifugal/centrifugo/v3 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/centrifugal/centrifugo/v4 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/centrifugal/centrifugo/v5 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 6.9.0go get github.com/centrifugal/centrifugo/v6@v6.9.0References
- https://github.com/centrifugal/centrifugo/security/advisories/GHSA-9468-v6mj-fppw[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-71485[ADVISORY]
- https://github.com/centrifugal/centrifugo/commit/84d38cea1dd2efa24375a148817a974c8727f4b0[FIX]
- https://github.com/centrifugal/centrifugo/pull/1182[FIX]
- https://github.com/centrifugal/centrifugo/releases/tag/v6.9.0[WEB]