Host Header Injection Vulnerability in Couch-Auth by Perfood
CVE-2025-70948

9.3CRITICAL

Key Information:

Vendor

Perfood

Vendor
CVE Published:
5 March 2026

What is CVE-2025-70948?

A severe host header injection vulnerability exists in the mailer component of Couch-Auth, specifically in version v0.26.0. This flaw enables attackers to manipulate the HTTP Host header, consequently allowing them to acquire sensitive reset tokens. Exploiting this vulnerability arises from the potential for unauthorized account access and takeover, notably putting user security at risk.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.