Skip to content

warpgate

v0.25.6 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 26d Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

bastion bastion-host https https-proxy infrastructure kubernetes
+9 more
mysql mysql-proxy pam postgresql-proxy privileged-access-management proxy rust ssh ssh-server

Affected surfaces

auth rbac

Summary

AI summary

GHSA-862h-v6cc-9757 and GHSA-2q37-6vxr-26jr fix critical authentication vulnerabilities in Websocket requests and SSH sessions.

Full changelog

Security fixes

GHSA-862h-v6cc-9757

In Websocket requests, a client could supply its own X-Wargate-Username header which would be appended to the upstream request, allowing the client to impersonate another user if the upstream relies on this header for authentication.

GHSA-2q37-6vxr-26jr

Incorrect authorization handling allowed an authenticated user to eavesdrop on another user's SSH session if they are able to obtain the session UUID.

Full Changelog: https://github.com/warp-tech/warpgate/compare/v0.25.5...v0.25.6

Security Fixes

  • GHSA-862h-v6cc-9757 — prevents client‑supplied X-Wargate-Username header from impersonating users in Websocket requests
  • GHSA-2q37-6vxr-26jr — fixes authorization handling to stop authenticated users from eavesdropping on other SSH sessions

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track warpgate

Get notified when new releases ship.

Sign up free

About warpgate

Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software

All releases →

Beta — feedback welcome: [email protected]