PT-2026-23511 · Unknown · @Perfood/Couch-Auth

CVE-2025-70948

·

Published

2026-03-05

·

Updated

2026-04-27

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @perfood/couch-auth version 0.26.0
Description A host header injection flaw exists in the mailer component. This allows attackers to obtain reset tokens and potentially take over accounts by manipulating the HTTP Host header. The affected component is used for authentication.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider validating and sanitizing the Host header before processing it within the mailer component.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70948
GHSA-QW8V-34WW-6Q9P

Affected Products

@Perfood/Couch-Auth