PT-2026-37205 · Azuracast · Azuracast
Offset
·
Published
2026-05-04
·
Updated
2026-05-13
·
CVE-2026-42606
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AzuraCast versions prior to 0.23.6
Description
The
ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header without a trusted proxy allowlist. An unauthenticated attacker can exploit this by injecting the X-Forwarded-Host header when triggering the forgot-password flow, poisoning the password reset URL sent to a user. If the victim clicks the link, their reset token is exfiltrated to the attacker's server. The attacker can then use this token on the legitimate instance to reset the victim's password and destroy their two-factor authentication (2FA) configuration, resulting in full account takeover.Recommendations
Update to version 0.23.6.
As a temporary workaround, restrict access to the
ApplyXForwarded middleware or ensure that the X-Forwarded-Host header is stripped or validated by a trusted reverse proxy before reaching the application.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azuracast