PT-2026-95492 · Anycable · Anycable

CVE-2026-63405

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions AnyCable versions prior to 1.6.15
Description The Pusher-compatible REST API in pusher/http.go includes the caller-supplied body md5 value in the HMAC input but fails to calculate the digest of the received request body or compare it with the signed value. This allows an attacker who obtains a legitimate signed POST request to retain the query parameters and auth signature while replacing the request body. Consequently, the Handler() and handleEvents() functions may accept and broadcast attacker-selected event content. Additionally, the lack of an auth timestamp freshness check allows captured signatures to be replayed indefinitely. This can lead to the forging of server-side events, modification of application state, or delivery of attacker-controlled messages to WebSocket clients within the signed request's application context.
Recommendations Update AnyCable to version 1.6.15.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63405
GHSA-5P54-WHVP-X327
GO-2026-6516

Affected Products

Anycable