PT-2026-23511 · Unknown · @Perfood/Couch-Auth

Published

2026-03-05

·

Updated

2026-04-27

·

CVE-2025-70948

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @perfood/couch-auth version 0.26.0
Description A host header injection flaw exists in the mailer component. This allows attackers to obtain reset tokens and potentially take over accounts by manipulating the HTTP Host header. The affected component is used for authentication.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider validating and sanitizing the Host header before processing it within the mailer component.

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-70948
GHSA-QW8V-34WW-6Q9P

Affected Products

@Perfood/Couch-Auth