{"id":"GO-2026-4988","summary":"DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header in github.com/l3montree-dev/devguard","details":"DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header in github.com/l3montree-dev/devguard","aliases":["CVE-2026-42300","GHSA-2g9v-7mr5-fgjg"],"modified":"2026-05-20T19:30:12.893001507Z","published":"2026-05-20T19:07:16Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4988"},"references":[{"type":"ADVISORY","url":"https://github.com/l3montree-dev/devguard/security/advisories/GHSA-2g9v-7mr5-fgjg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42300"},{"type":"FIX","url":"https://github.com/l3montree-dev/devguard/commit/6f38310bf93b2a63df3055038f4da82b1f4e6d9a"}],"affected":[{"package":{"name":"github.com/l3montree-dev/devguard","ecosystem":"Go","purl":"pkg:golang/github.com/l3montree-dev/devguard"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4988.json"}}],"schema_version":"1.7.5"}