GO · JULY 2026 · EARLY WARNING

Cosmos-Server's Public-Devices Endpoint Discloses Metadata

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-5FQM-CC34-FCF5Severity: HIGH

An early warning has been issued regarding Cosmos-Server's public-devices endpoint, which reportedly discloses device metadata to any requester that supplies a non-empty Authorization header. The endpoint appears to accept arbitrary bearer tokens without validation.

What happened

The Cosmos-Server's constellation public-devices endpoint is under investigation for disclosing Constellation device metadata to any requester that supplies a non-empty Authorization header. The endpoint is reported to accept arbitrary bearer tokens without validation, potentially allowing unauthorized access to device metadata. Affected versions include cosmos-server (go) version 0.22.18. It is recommended to review the usage of the public-devices endpoint for potential unauthorized access and to upgrade to a fixed version of cosmos-server once available. For more details, consult the primary sources: [GHSA-2rx5-2g7j-2659](https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-2rx5-2g7j-2659) and [GHSA-5fqm-cc34-fcf5](https://github.com/azukaar/Cosmos-Server/security/advisories/GHSA-5fqm-cc34-fcf5).

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If cosmos-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats