Password Reset Vulnerability in Sub2API AI Gateway by Wei-Shaw
CVE-2026-27812
8HIGH
What is CVE-2026-27812?
Sub2API, an AI API gateway platform, is susceptible to a password reset poisoning vulnerability resulting from improper trust in host and forwarded headers. This flaw affects versions prior to 0.1.85, enabling attackers to manipulate password reset links by injecting their domain. Such exploitation could facilitate unauthorized account access. Users are advised to update to version 0.1.85 to rectify this vulnerability. If an upgrade cannot be performed immediately, disabling the 'forgot password' feature is recommended to mitigate risk until the patch can be applied.
Affected Version(s)
sub2api < 0.1.85
