SCA: security update for github.com/azukaar/cosmos-server (GHSA-2rx5-2g7j-2659)

medium Tenable Self-Hosted Container Security Plugin ID 445443

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Cosmos provides users the ability self-host a home server by acting as a secure gateway to your
application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can
return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-
user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid
x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can
supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application
trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks,
allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue
is fixed in version 0.22.19. (CVE-2026-49446)

Solution

Update the github.com/azukaar/cosmos-server library and its related packages to version 0.22.19 or later.

See Also

https://github.com/advisories/GHSA-2rx5-2g7j-2659

Plugin Details

Severity: Medium

ID: 445443

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 7/29/2026

Updated: 9/16/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.63

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.7

Temporal Score: 5

Vector: CVSS2#AV:A/AC:L/Au:M/C:C/I:C/A:N

CVSS Score Source: CVE-2026-49446

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.3

Vector: CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/28/2026

Vulnerability Publication Date: 7/28/2026

Reference Information

CVE: CVE-2026-49446