Junglewise Threat Intelligence

CVE-2026-48031: go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT sig

CVE-2026-48031 · Severity: critical · CVSS 9.1 · Published 2026-08-03

Vendors: Go.

Executive brief

A popular Go-based web application template contains a hardcoded security key used to sign login tokens. Because this key is publicly known, an attacker can create their own valid login tokens to impersonate any user, including administrators. This allows unauthorized access to sensitive data and the ability to modify system information without a valid password.

Technical details

The application utilizes a hardcoded JWT signing secret ("random") defined in both the template environment file and as a programmatic fallback in the server configuration. While a mitigation was present to replace the string "random" with a generated key, the replacement was non-persistent (stored only in memory), causing session loss on restarts, and failed to check for other common weak secrets. An unauthenticated remote attacker can use the known secret to sign forged HS256 JWT tokens with arbitrary claims, such as admin roles. This results in a complete authentication bypass across all protected API endpoints. The vulnerability is addressed in PR #31 by implementing a blocklist of weak secrets and requiring a minimum secret length.

Affected products

  • dhax go-base < 0.0.0-20260517152733-cc82b9740fa6

Timeline

  • 2026-05-17: patched: Fix merged in PR #31
  • 2026-05-20: disclosed: Initial advisory publication
  • 2026-06-10: advisory: Updated advisory published on GitHub

References