THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5p54-whvp-x327 (medium) — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

[GHSA] GHSA-5p54-whvp-x327 (medium) — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

medgithub_advisoriesPublished 2026-09-18

GHSA-5p54-whvp-x327 Severity: medium CVE: CVE-2026-63405

AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body

### Summary The Pusher-compatible REST API includes `body_md5` in the HMAC signature string but never computes or verifies the MD5 of the received HTTP body, allowing anyone who observes a signed request to replay it with an entire

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5p54-whvp-x327