Description
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send.

Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set.

Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset.

The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.
Published: 2026-08-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Default emails in Dancer2::Plugin::Auth::Extensible contain a link formed from the request Host header or X-Forwarded‑Host when behind a proxy. An attacker can set this header to any value, causing password‑reset or welcome emails to reference a host controlled by the attacker. When a user clicks the forged link, the attacker receives a valid reset code and can change the account password, effectively taking over the account without needing the original credentials.

Affected Systems

The vulnerability affects all installations of ABEVERLEY's Dancer2::Plugin::Auth::Extensible through version 0.713. Earlier releases (0.711 and below) read untrusted host information directly, while 0.712 and 0.713 provide a configurable uri_base but, if left unset, also default to the untrusted request data.

Risk and Exploitability

The security impact is high: any user of the affected application can be compromised by merely following an email link. Exploitation requires only the ability to forge a Host header, which is trivial for an attacker posing as the mail sender or an intermediary. The CVSS score is 9.8. The EPSS score is < 1%. The vulnerability is not currently in CISA’s KEV catalogue, yet it remains a significant risk for any exposed instance.

Generated by OpenCVE AI on August 18, 2026 at 00:18 UTC.

Remediation

Vendor Workaround

No fixed release is available. In 0.712 and later, set the uri_base configuration key to the application's own base URL; otherwise reject requests whose host is not an expected application hostname, including X-Forwarded-Host under behind_proxy.


OpenCVE Recommended Actions

  • Configure the uri_base key to the application’s concrete base URL so that locally generated links use a trusted host value.
  • If the app operates behind a proxy, reject requests where the Host or X-Forwarded-Host header does not match the expected base URL, or limit acceptance to known proxies only.
  • Stay informed of vendor updates and upgrade to a fixed release as soon as it is available.

Generated by OpenCVE AI on August 18, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Abeverley
Abeverley dancer2::plugin::auth::extensible
Vendors & Products Abeverley
Abeverley dancer2::plugin::auth::extensible

Sat, 15 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
References

Sat, 15 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set. Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset. The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.
Title Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
Weaknesses CWE-640
References

Subscriptions

Abeverley Dancer2::plugin::auth::extensible
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-08-17T20:27:51.814Z

Reserved: 2026-07-14T01:03:59.438Z

Link: CVE-2026-15689

cve-icon Vulnrichment

Updated: 2026-08-15T19:06:35.186Z

cve-icon NVD

Status : Deferred

Published: 2026-08-15T14:17:06.480

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-15689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T00:30:05Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password