{"id":"GHSA-j9wf-6r2x-hqmx","aliases":["GO-2026-4528"],"url":"https://o3.security/vulnerability/GHSA-j9wf-6r2x-hqmx","summary":"Centrifugo v6.6.0 dependency vulnerabilities","details":"### Summary                                                                                                                                                                                              \n                                                                                                                                                                                                           \n  Centrifugo v6.6.0 binary is compiled with **Go 1.25.5** and                                                                                                                       \n  statically links `github.com/quic-go/webtransport-go v0.9.0`, having **7 known                                                                                                                      \n  CVEs**\n\n  **Go standard library — compiled with Go 1.25.5:**\n\n  | CVE | Severity | CVSS | Fixed In |\n  |-----|----------|------|----------|\n  | CVE-2025-68121 | **CRITICAL** | 10.0 | Go 1.25.7, 1.24.13 |\n  | CVE-2025-61726 | HIGH | 7.5 | Go 1.25.6, 1.24.12 |\n  | CVE-2025-61728 | MEDIUM | 6.5 | Go 1.25.6, 1.24.12 |\n  | CVE-2025-61730 | MEDIUM | 5.3 | Go 1.25.6, 1.24.12 |\n\n  **Direct dependency `github.com/quic-go/webtransport-go` — pinned at v0.9.0\n  (`go.mod` line 34):**\n\n  | CVE | Severity | CVSS | Fixed In |\n  |-----|----------|------|----------|\n  | CVE-2026-21434 | MEDIUM | 5.3 | webtransport-go v0.10.0 |\n  | CVE-2026-21435 | MEDIUM | 5.3 | webtransport-go v0.10.0 |\n  | CVE-2026-21438 | MEDIUM | 5.3 | webtransport-go v0.10.0 |","published":"2026-02-19T22:07:13Z","modified":"2026-02-23T19:41:19.423703Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/centrifugal/centrifugo/v6","fixedVersion":"6.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/centrifugal/centrifugo/security/advisories/GHSA-j9wf-6r2x-hqmx"},{"type":"PACKAGE","url":"https://github.com/centrifugal/centrifugo"},{"type":"WEB","url":"https://github.com/centrifugal/centrifugo/releases/tag/v6.6.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-23T19:41:19.423703Z"}}