GHSA-8x2m-938h-j94gHighCVSS 7.5

A flaw was found in search-v2-api. The authentication middleware in the affected component...

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an Upgrade: websocket header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the /federated endpoint with the Upgrade: websocket header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.

🔗 References (4)