Information Disclosure Vulnerability in Cosmos Server by Azukaar
CVE-2026-49447

5.3MEDIUM

Key Information:

Vendor

Azukaar

Vendor
CVE Published:
28 July 2026

What is CVE-2026-49447?

The Cosmos Server, designed to enable users to self-host a secure gateway for their applications, has a vulnerability in version 0.22.18. The issue arises in the GET /cosmos/api/constellation/public-devices endpoint, where Constellation device metadata is exposed to any requester that sends a non-empty Authorization header. Although the header's Bearer prefix is removed, the token is not validated, allowing unauthorized access to sensitive metadata. Users are advised to upgrade to version 0.22.19, where this issue has been addressed.

Affected Version(s)

Cosmos-Server 0.22.18

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.