PT-2026-23511 · Unknown · @Perfood/Couch-Auth
Published
2026-03-05
·
Updated
2026-04-27
·
CVE-2025-70948
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@perfood/couch-auth version 0.26.0
Description
A host header injection flaw exists in the mailer component. This allows attackers to obtain reset tokens and potentially take over accounts by manipulating the HTTP Host header. The affected component is used for authentication.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider validating and sanitizing the Host header before processing it within the mailer component.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Perfood/Couch-Auth