Information Disclosure Vulnerability in Cosmos Server by Azukaar
CVE-2026-49447
5.3MEDIUM
What is CVE-2026-49447?
The Cosmos Server, designed to enable users to self-host a secure gateway for their applications, has a vulnerability in version 0.22.18. The issue arises in the GET /cosmos/api/constellation/public-devices endpoint, where Constellation device metadata is exposed to any requester that sends a non-empty Authorization header. Although the header's Bearer prefix is removed, the token is not validated, allowing unauthorized access to sensitive metadata. Users are advised to upgrade to version 0.22.19, where this issue has been addressed.
Affected Version(s)
Cosmos-Server 0.22.18
