PT-2026-37205 · Azuracast · Azuracast

Offset

·

Published

2026-05-04

·

Updated

2026-05-13

·

CVE-2026-42606

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AzuraCast versions prior to 0.23.6
Description The ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header without a trusted proxy allowlist. An unauthenticated attacker can exploit this by injecting the X-Forwarded-Host header when triggering the forgot-password flow, poisoning the password reset URL sent to a user. If the victim clicks the link, their reset token is exfiltrated to the attacker's server. The attacker can then use this token on the legitimate instance to reset the victim's password and destroy their two-factor authentication (2FA) configuration, resulting in full account takeover.
Recommendations Update to version 0.23.6. As a temporary workaround, restrict access to the ApplyXForwarded middleware or ensure that the X-Forwarded-Host header is stripped or validated by a trusted reverse proxy before reaching the application.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42606
GHSA-GV7R-3MR9-H5X8

Affected Products

Azuracast