PT-2026-95492 · Anycable · Anycable
CVE-2026-63405
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
AnyCable versions prior to 1.6.15
Description
The Pusher-compatible REST API in
pusher/http.go includes the caller-supplied body md5 value in the HMAC input but fails to calculate the digest of the received request body or compare it with the signed value. This allows an attacker who obtains a legitimate signed POST request to retain the query parameters and auth signature while replacing the request body. Consequently, the Handler() and handleEvents() functions may accept and broadcast attacker-selected event content. Additionally, the lack of an auth timestamp freshness check allows captured signatures to be replayed indefinitely. This can lead to the forging of server-side events, modification of application state, or delivery of attacker-controlled messages to WebSocket clients within the signed request's application context.Recommendations
Update AnyCable to version 1.6.15.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anycable