🛡️ CVE-2026-58399 — auth

🔴 CVSS 9.5 — Critical ✅ No Known Exploit CWE-290 NVD
9.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth v2.2.0 appears to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers.

The validateToken middleware contains a service-to-service bypass for auth-user: service-brother when req.get('host').startsWith(getHostName()). Both values involved in the check can be influenced by an unauthenticated HTTP client: auth-user is a request header, and Host is also client-controlled. As a result, a remote unauthenticated attacker can send a request with crafted headers and bypass token validation before the normal legacy/JWT/OIDC validation logic runs.

Impact:

An attacker may be able to access routes protected by validateToken() without a valid token. In deployments where downstream services trust auth-user or is-* headers, this may also lead to privilege escalation.

Affected package:

@acastellon/auth v2.2.0

Affected code:

auth.js, validateToken()

The issue is related to the service-brother bypass and getHostName() check.

Example request:

```

GET /protected HTTP/1.1

Host: <configured CNAME or hostname>

auth-user: service-brother

is-admin: true

```

Expected behavior:

The request should require a valid authentication token.

Actual behavior:

The middleware calls next() before token validation.

Fix implemented in v2.3.0+:

Removed the spoofable bypass.

Always sanitize incoming auth-user and is-* headers.

Added mTLS client certificate based service auth (with optional TRUSTED_MTLS_SERVICES allowlist).

Updated consumers (rest, graphql, dns-client) for mTLS support.

Unit tests added for sanitization + mTLS path.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality high, integrity high, availability none.

Weakness class

CVE-2026-58399 is classified as CWE-290: Authentication Bypass by Spoofing. Identity is inferred from something an attacker can forge, such as a header or address.

Affected software

CVE-2026-58399 is recorded against 2 packages.

  • @acastellon/auth
  • unknown

Timeline and source

Published on 18 June 2026 and last revised on 1 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
github.com (Web)
github.com (Package)
www.npmjs.com (Web)

Details

Severity CRITICAL
CVSS Score 9.5
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-290
Public Exploit ✅ No
Source NVD
Published 2026-06-18
Updated 2026-08-12
Modified 2026-07-01
Fix URL N/A

Affected Packages

Software From version Fixed in
@acastellon/auth
unknown

Exploit Protection

Are you running auth?

CVE-2026-58399 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-58399 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.