Vulnerability in AnyCable Pusher-Compatible REST API Affects Communication Security
CVE-2026-63405

5.9MEDIUM

Key Information:

Vendor

Anycable

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-63405?

Prior to version 1.6.15, the Pusher-compatible REST API in AnyCable did not properly validate the MD5 digest of the request body against the signed value. This allowed an attacker to capture a legitimate signed POST request, modify the body content, and replace event data, which could lead to unauthorized server-side events and altered application states. Additionally, the lack of a freshness check for the auth_timestamp permitted replay attacks, allowing attackers to continuously exploit the captured signature. This vulnerability could enable attackers to send manipulated messages to WebSocket clients, ultimately compromising the security of the communication channel.

Affected Version(s)

anycable < 1.6.15

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.