Junglewise Threat Intelligence

CVE-2026-44592: Wavelens Gradient unauthenticated worker registration and cache poisoning

CVE-2026-44592 · Severity: critical · CVSS 9.4 · Published 2026-05-14

Executive brief

Gradient, a continuous integration system used for building and testing software, contains a critical security flaw in its worker registration process. An unauthenticated attacker can register themselves as a trusted worker and gain access to private repository credentials and internal build jobs. This allows an attacker to poison the software supply chain by injecting malicious code into build artifacts, potentially compromising any system that relies on the affected CI environment.

Technical details

A vulnerability in Gradient's authentication logic (specifically in `backend/proto/src/handler/session.rs`) allows unauthenticated attackers to register as workers by providing a new, unregistered UUID when `GRADIENT_DISCOVERABLE` is set to true. The system incorrectly grants these sessions 'PeerAuth::Open' status, providing visibility into jobs across all organizations. Furthermore, the protocol handler fails to verify job ownership during `NarPush` and `NarUploaded` operations, allowing an attacker to overwrite arbitrary store paths in `nar_storage` and manipulate the `cached_path` table. This can lead to cache poisoning and the distribution of malicious Nix store paths to downstream clients. The issue is fixed in version 1.1.1 by enforcing authentication for inbound worker connections.

Affected products

  • wavelens Gradient >= 63e3b30, <= 1.1.0

Timeline

  • 2026-04-12: other: Vulnerability introduced during challenge-response auth rewrite
  • 2026-05-02: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD
  • 2026-05-14: patched: Fixed in version 1.1.1

References