CVE-2026-32301Disclosure(centrifugal / centrifugo)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch centrifugal centrifugo systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthenticated attacker can craft a JWT with a malicious iss or aud claim value that gets interpolated into the JWKS fetch URL before the token signature is verified, causing Centrifugo to make an outbound HTTP request to an attacker-controlled destination. This vulnerability is fixed in 6.7.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • centrifugo

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
centrifugo

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-12: 2Mentions · 2026-03-13: 2Mentions · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-13: 2Technical Details · 2026-03-18: 103-1203-1303-18
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-122
Disclosure2
2026-03-132
Disclosure1Patch1
2026-03-181
General1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    General

    `Centrifugo` is affected by an SSRF vulnerability (CVE-2026-32301) via unverified JWT claims in JWKS URL resolution. This can lead to internal network reconnaissance. Monitor for official #security advisories. #SSRF #JWT https://www.pulsepatch.io/posts/cve-2026-32301-centrifugo-ssrf

    Post summary

    The tweet reports a newly identified SSRF vulnerability in Centrifugo with some technical details, but lacks a PoC, exploit code, or evidence of active exploitation.

    0000032
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32301 - Critical Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoi... https://www.thehackerwire.com/vulnerability/CVE-2026-32301/ https://t.co/piuiAmnroR

    Post summary

    A new critical SSRF vulnerability (CVE‑2026‑32301) has been disclosed for Centrifugo versions before 6.7.0, with technical details provided but no proof of exploitation or patch information.

    0000043
    135 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32301: CRITICAL] Centrifugo v6.7.0 addresses a SSRF vulnerability allowing attackers to manipulate JWKS endpoints. Update to the latest version to secure your real-time messaging server.#cve,CVE-2026-32301,#cybersecurity https://cvefind.com/CVE-2026-32301

    Post summary

    This tweet issues a patch reminder, advising users to update Centrifugo to the latest version to mitigate a critical SSRF vulnerability that could let attackers manipulate JWKS endpoints.

    0000036
    602 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32301 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with … https://www.cve.org/CVERecord?id=CVE-2026-32301

    Post summary

    The post reports that CVE‑2026‑32301 is a Server‑Side Request Forgery vulnerability affecting Centrifugo versions prior to 6.7.0, with no mention of exploits, patches, or PoC details.

    0000085
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32301: Centrifugo: SSRF via unverified ... JWT claim injection bypasses signature validation to trigger SSRF - classic cart-before-horse auth flaw that turns temp... https://zerodaysignal.com/vulnerability/CVE-2026-32301 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a zero‑day vulnerability (CVE‑2026‑32301) in Centrifugo that permits SSRF through a JWT claim injection that bypasses signature validation. A reference link to Zeroday Signal provides further details and potential PoC information.

    0000071
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcentrifugalcentrifugo---

Explore more