Description
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send.

Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set.

Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset.

The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Default emails in Dancer2::Plugin::Auth::Extensible contain a link formed from the request Host header or X-Forwarded-Host when behind a proxy. An attacker can set this header to any value, causing password‑reset or welcome emails to reference a host controlled by the attacker. When a user clicks the forged link, the attacker receives a valid reset code and can change the account password, effectively taking over the account without needing the original credentials.

Affected Systems

The vulnerability affects all installations of ABEVERLEY's Dancer2::Plugin::Auth::Extensible through version 0.713. Earlier releases (0.711 and below) read untrusted host information directly, while 0.712 and 0.713 provide a configurable uri_base but, if left unset, also default to the untrusted request data.

Risk and Exploitability

The security impact is high: any user of the affected application can be compromised by merely following an email link. Exploitation requires only the ability to forge a Host header, which is trivial for an attacker posing as the mail sender or an intermediary. The CVSS score is not listed, and EPSS is not available, but the absence of a filter makes this a severe flaw. The vulnerability is not currently in CISA’s KEV catalogue, yet it remains a significant risk for any exposed instance.

Generated by OpenCVE AI on August 15, 2026 at 15:15 UTC.

Remediation

Vendor Workaround

No fixed release is available. In 0.712 and later, set the uri_base configuration key to the application's own base URL; otherwise reject requests whose host is not an expected application hostname, including X-Forwarded-Host under behind_proxy.


OpenCVE Recommended Actions

  • Configure the uri_base key to the application’s concrete base URL so that locally generated links use a trusted host value.
  • If the app operates behind a proxy, reject requests where the Host or X-Forwarded-Host header does not match the expected base URL, or limit acceptance to known proxies only.
  • Stay informed of vendor updates and upgrade to a fixed release as soon as it is available.

Generated by OpenCVE AI on August 15, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set. Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset. The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.
Title Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
Weaknesses CWE-640
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-15T13:25:26.318Z

Reserved: 2026-07-14T01:03:59.438Z

Link: CVE-2026-15689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T14:17:06.480

Modified: 2026-08-15T14:17:06.480

Link: CVE-2026-15689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T15:30:09Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password