28Hus opened a new issue, #1557: URL: https://github.com/apache/dubbo-admin/issues/1557
# Hard-coded session signing key allows authentication bypass in Go-based Dubbo Admin ## Summary The Go-based Dubbo Admin hard-codes the signing key used by its client-side session cookie. The same cookie store is used by the authentication middleware, which grants access when the session contains a `user` value. There is no server-side session lookup or revocation check to prevent forged cookies. The issue remains present at commit [1e56a0a](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86). ## Evidence The session store is initialized with a fixed value: [pkg/console/component.go#L86](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86) The store is registered as the application-wide session middleware: [pkg/console/component.go#L86-L88](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86-L88) The authentication middleware only checks whether `session.Get("user")` is present: [pkg/console/component.go#L135-L151](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L135-L151) ## Impact An attacker who can read the public source code can generate a valid session cookie containing an arbitrary user value. The forged cookie is accepted as an authenticated session and can be used to access endpoints protected only by this middleware. The issue was reproduced in a controlled local deployment. A request without a session cookie was rejected, while a forged cookie was accepted. Detailed request, response, and PoC material can be provided privately. ## Timeline - **December 11, 2025:** I privately reported the hard-coded session signing key and the lack of server-side validation to the Apache and Dubbo security teams. - **January 12, 2026:** Dubbo Admin published the public pre-release `v0.7.0-pre`. - **March-April 2026:** Follow-ups confirmed that the hard-coded key remained present. I also offered to prepare a pull request with a remediation. No response was received to these follow-ups as of September 15, 2026. - **September 15, 2026:** The key remains present at commit [1e56a0a](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86). This public Issue is opened to request project attention and coordinate a fix. ## Recommended Fix Remove the hard-coded session signing key. The application should require a deployment-specific cryptographically random secret, generate one during installation, or fail startup when no secure value is configured. ## Collaboration This Issue requests clarification and coordinates remediation following the previous private disclosure. I will prepare a pull request or provide a patch through the channel preferred by the maintainers. This issue is part of my ongoing research. If you have any questions about this report, please feel free to @mention me at any time. I would be very happy to assist with improving the security of Dubbo Admin. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
