
🚨 CRITICAL - Auth middleware bypass via spoofed headers (@acastellon/auth) (CVE-2026-58399) CVE-2026-58399 is an authentication bypass in the @acastellon/auth package where the validateToken() middleware can be tricked into skipping legacy/JWT/OIDC token validation. The root cause is improper trust of spoofable headers and flawed request flow control that allows next() to be called before authentication checks complete. An unauthenticated attacker can exploit this remotely by sending crafted requests with forged auth-user and Host headers to trigger a service-to-service bypass path. Impact is unauthorized access to routes protected by validateToken(), with potential privilege escalation and lateral movement in environments where downstream services trust auth-user (or related) headers. 👉 Affected: @acastellon/auth < 2.3.0 | Upgrade to 2.3.0
Post summary
A critical auth middleware bypass in @acastellon/auth (CVE-2026-58399) is disclosed with technical details and advises users to upgrade to version 2.3.0 to remediate the issue.
