THREAT OPS › Threat News › [GHSA] GHSA-5p54-whvp-x327 (medium) — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
[GHSA] GHSA-5p54-whvp-x327 (medium) — AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
GHSA-5p54-whvp-x327 Severity: medium CVE: CVE-2026-63405
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
### Summary The Pusher-compatible REST API includes `body_md5` in the HMAC signature string but never computes or verifies the MD5 of the received HTTP body, allowing anyone who observes a signed request to replay it with an entire
Indicators of compromise
- CVE-2026-63405cve
Original source: https://github.com/advisories/GHSA-5p54-whvp-x327