Password Reset Vulnerability in Sub2API AI Gateway by Wei-Shaw
CVE-2026-27812

8HIGH

Key Information:

Vendor

Wei-shaw

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-27812?

Sub2API, an AI API gateway platform, is susceptible to a password reset poisoning vulnerability resulting from improper trust in host and forwarded headers. This flaw affects versions prior to 0.1.85, enabling attackers to manipulate password reset links by injecting their domain. Such exploitation could facilitate unauthorized account access. Users are advised to update to version 0.1.85 to rectify this vulnerability. If an upgrade cannot be performed immediately, disabling the 'forgot password' feature is recommended to mitigate risk until the patch can be applied.

Affected Version(s)

sub2api < 0.1.85

References

CVSS V4

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.