CVE Explorer
CVE-2026-48031
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (line 35), so the appl
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"go-base","vendor":"dhax","versions":[{"status":"affected","version":"2026-05-18"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-798","description":"CWE-798: Use of Hard-coded Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/dhax/go-base/commit/cc82b9740fa6b08e0fad409cd4b418e240dd0e00","tags":["x_refsource_MISC"],"url":"https://github.com/dhax/go-base/commit/cc82b9740fa6b08e0fad409cd4b418e240dd0e00"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/references/2
{"name":"https://github.com/dhax/go-base/pull/31","tags":["x_refsource_MISC"],"url":"https://github.com/dhax/go-base/pull/31"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/references/1
{"name":"https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bcdf7ef442303f5a3fdfba7be2487e4b660ad3968219946da3048fd58937425b · sha256:5531ca88fb49d87b… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.