CVE-2026-58399Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers. The validateToken middleware contains a service-to-service bypass for auth-user: service-brother when req.get('host').startsWith(getHostName()). Both values involved in the check can be influenced by an unauthenticated HTTP client: auth-user is a request header, and Host is also client-controlled. As a result, a remote unauthenticated attacker can send a request with crafted headers and bypass token validation before the normal legacy/JWT/OIDC validation logic runs. A fix has been implemented in v2.3.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Auth middleware bypass via spoofed headers (@acastellon/auth) (CVE-2026-58399) CVE-2026-58399 is an authentication bypass in the @acastellon/auth package where the validateToken() middleware can be tricked into skipping legacy/JWT/OIDC token validation. The root cause is improper trust of spoofable headers and flawed request flow control that allows next() to be called before authentication checks complete. An unauthenticated attacker can exploit this remotely by sending crafted requests with forged auth-user and Host headers to trigger a service-to-service bypass path. Impact is unauthorized access to routes protected by validateToken(), with potential privilege escalation and lateral movement in environments where downstream services trust auth-user (or related) headers. 👉 Affected: @acastellon/auth < 2.3.0 | Upgrade to 2.3.0

    Post summary

    A critical auth middleware bypass in @acastellon/auth (CVE-2026-58399) is disclosed with technical details and advises users to upgrade to version 2.3.0 to remediate the issue.

    00000102
    232 followersView on X

Explore more