CVE-2025-70948Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-644

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-03-05); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-16: 1Mentions · 2026-04-27: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-04-27: 103-0503-0803-0903-1604-27
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-081
Disclosure1
2026-03-091
Disclosure1
2026-03-161
General1
2026-04-271
Patch1
Full discourse5 posts
  • أحمد رضا 🇵🇸@HunterXReda
    General

    الحمدلله At the very end of 2025, I discovered and reported multiple CVEs. Two high-severity ones found in the couch-auth NPM package are now officially published. CVE-2025-70948 https://www.cve.org/CVERecord?id=CVE-2025-70948 CVE-2025-70949 https://www.cve.org/CVERecord?id=CVE-2025-70949 Stay tuned for what's next

    Post summary

    A user disclosed that they found and reported two CVEs in the couch‑auth NPM package, providing links to CVE records but offering no further technical, exploit, or patch information.

    20060264
    289 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 CRITICAL: CVE-2025-70948 (CVSS 9.3) Host header injection in @perfood/couch-auth v0.26.0 enables account takeover via reset token theft. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/4eoyeAAdVF

    Post summary

    The tweet alerts to a critical host header injection vulnerability (CVE-2025-70948) in perfood/couch-auth v0.26.0 that can lead to account takeover via reset token theft; users are urged to patch immediately.

    00000527
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70948 A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover v… https://www.cve.org/CVERecord?id=CVE-2025-70948

    Post summary

    The statement discloses a host header injection vulnerability in @perfood/couch-auth v0.26.0, enabling attackers to steal reset tokens and perform account takeover.

    00000219
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-70948 - Critical A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP ... https://www.thehackerwire.com/vulnerability/CVE-2025-70948/ https://t.co/yCX3eW28Ww

    Post summary

    This tweet announces a host header injection vulnerability in perfood/couch-auth v0.26.0 that enables attackers to steal reset tokens and take over accounts, with no PoC, exploit code, patch, or evidence of active exploitation.

    00000109
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70948 Host Header Injection in @perfood/couch-auth v0.26.0 Enab... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70948 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A tweet announces CVE-2025-70948 as a Host Header Injection vulnerability in @perfood/couch-auth v0.26.0, providing a link to vulnerability details without evidencing a PoC, exploit code, or patch.

    0000079
    4.0K followersView on X

Explore more