{"id":"GHSA-2g9v-7mr5-fgjg","summary":"DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header","details":"### Impact\nThe `SessionMiddleware` accepts a client-supplied `X-Admin-Token` HTTP request header and uses its raw string value as the authenticated `userID` when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation `admin` or `owner`, this gives the attacker full control over that organisation's DevGuard resources.\n\n### Patches\nThe release v1.2.2 patches this issue. Update your DevGuard API Instances to this version.\n\n### Workarounds\nConfigure a reverse proxy to strip the `X-Admin-Token` header before sending requests to the DevGuard API.\n\n### Resources\nFixed commit: https://github.com/l3montree-dev/devguard/commit/6f38310bf93b2a63df3055038f4da82b1f4e6d9a","aliases":["CVE-2026-42300","GO-2026-4988"],"modified":"2026-05-20T19:41:29.664884737Z","published":"2026-05-05T20:58:27Z","database_specific":{"nvd_published_at":"2026-05-12T18:17:24Z","cwe_ids":["CWE-288"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-05-05T20:58:27Z"},"references":[{"type":"WEB","url":"https://github.com/l3montree-dev/devguard/security/advisories/GHSA-2g9v-7mr5-fgjg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42300"},{"type":"WEB","url":"https://github.com/l3montree-dev/devguard/commit/6f38310bf93b2a63df3055038f4da82b1f4e6d9a"},{"type":"PACKAGE","url":"https://github.com/l3montree-dev/devguard"}],"affected":[{"package":{"name":"github.com/l3montree-dev/devguard","ecosystem":"Go","purl":"pkg:golang/github.com/l3montree-dev/devguard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-2g9v-7mr5-fgjg/GHSA-2g9v-7mr5-fgjg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}