CVE-2026-49447
MEDIUMCosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Title source: cnaDescription
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18, `GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty Authorization header. The handler strips the string Bearer from the header but never validates the resulting token and never uses it in the database query. This vulnerability is fixed in 0.22.19.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5
X_Refsource_Misc x_refsource_misc
https://github.com/azukaar/Cosmos-Server/commit/59c561d686c8f9843b3e092b50f6346c481d8bbf
X_Refsource_Misc x_refsource_misc
https://github.com/azukaar/Cosmos-Server/releases/tag/v0.22.19
Scores
CVSS v3
5.3
EPSS
0.0022
EPSS Percentile
13.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (2)
azukaar/Cosmos-Server
0.22.18
azukaar/cosmos-server
0.22.18 - 0.22.19Go
Published
Jul 28, 2026
Tracked Since
Jul 29, 2026