Description
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass and User Impersonation
Action: Immediate Patch
AI Analysis

Impact

Cosmos servers use a token middleware that, in earlier releases, returned a request through the Constellation tunnel before clearing the user‑identifying headers (x-cosmos-user, x-cosmos-role, x-cosmos-user-role, x-cosmos-mfa) and before executing the AdminOnlyWithRedirect check. An attacker possessing a valid x‑cstln‑auth API key for an enrolled device can supply a chosen x‑cosmos-user header to a route configured with AuthEnabled. If the upstream application trusts this forward‑auth header, Cosmos fails to perform its own JWT, password, MFA, and admin‑only validation, enabling the attacker to impersonate any user or gain administrative access to resources behind the proxy. The issue was fixed in version 0.22.19.

Affected Systems

The affected product is Cosmos‑Server from azukaar, with vulnerable releases older than version 0.22.19. Users running any 0.22.18 or earlier build are susceptible.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.1, indicating a moderate severity, and it is not yet listed in CISA’s KEV catalog. Because the exploit requires a valid x‑cstln‑auth key for an enrolled device and so‑called Constellation Nebula tunnel access, the attack vector is highly targeted and inferred to be internal or within trusted networks. The EPSS score is < 1%, indicating a very low exploitation probability, yet the potential for user impersonation and admin data exposure makes it a serious concern for affected deployments.

Generated by OpenCVE AI on September 17, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Cosmos‑Server to version 0.22.19 or later to receive the patch that removes the vulnerability
  • If updating is not immediately possible, block or disconnect the Constellation Nebula tunnel to prevent the malicious forward‑auth headers from reaching the server
  • Reconfigure the application behind the tunnel to ignore or strip any forward‑auth headers before processing requests, thereby restoring the original authentication flow

Generated by OpenCVE AI on September 17, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2rx5-2g7j-2659 Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
History

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Azukaar
Azukaar cosmos-server
Vendors & Products Azukaar
Azukaar cosmos-server

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cosmos-user-role, and x-cosmos-mfa headers and before invoking AdminOnlyWithRedirect. An attacker with a valid x-cstln-auth API key for an enrolled device who reaches Cosmos through the Constellation Nebula tunnel can supply a chosen x-cosmos-user value to a route with AuthEnabled enabled when the upstream application trusts that forward-auth header. The request can bypass Cosmos JWT, password, MFA, and AdminOnly checks, allowing user impersonation and admin-tier reads or writes exposed by the proxied application. This issue is fixed in version 0.22.19.
Title Cosmos: Authentication bypass via forward-auth header smuggling on Constellation tunnel in Cosmos-Server
Weaknesses CWE-285
CWE-290
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Azukaar Cosmos-server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:50:54.216Z

Reserved: 2026-05-30T02:43:33.106Z

Link: CVE-2026-49446

cve-icon Vulnrichment

Updated: 2026-09-15T14:50:50.514Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:16.747

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-49446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:30:06Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-290

    Authentication Bypass by Spoofing