← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 15, 2026 · 14:17via CVEFeed

CVE-2026-15689 - Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send

Brief

CVE ID : CVE-2026-15689

Published : Aug. 15, 2026, 2:17 p. m.

  • 6 hours, 49 minutes ago

Description : Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send.

Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request-base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing.

The welcome mail takes the same path when the application calls create_user with email_welcome set.

Through 0.

Read more on CVEFeed