A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-05T20:58:53.693Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70948
No data.
Status : Received
Published: 2026-03-05T21:16:13.737
Modified: 2026-03-05T21:16:13.737
Link: CVE-2025-70948
No data.
OpenCVE Enrichment
No data.