CVE detail
CVE-2023-39655 — CVE-2023-39655
Published 2024-01-03 · Modified 2026-06-17 · Vendor perfood · Product couchauth · Source nvd
CRITICAL
severity
CVSS-derived band
0.0052
EPSS probability
exploitation probability, 30d
41.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References