A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in password reset emails) using the user-supplied Host header. This allows remote attackers to poison the password reset link sent to a victim,
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in password reset emails) using the user-supplied Host header. This allows remote attackers to poison the password reset link sent to a victim, | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-20T16:43:05.241Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26747
No data.
Status : Received
Published: 2026-02-20T17:25:56.023
Modified: 2026-02-20T17:25:56.023
Link: CVE-2026-26747
No data.
OpenCVE Enrichment
No data.