Giuseppe Paternicola[verified]@giuseppe_1337Patch
The tweet alerts to a critical host header injection vulnerability (CVE-2025-70948) in perfood/couch-auth v0.26.0 that can lead to account takeover via reset token theft; users are urged to patch immediately.
أحمد رضا 🇵🇸@HunterXRedaGeneral
A user disclosed that they found and reported two CVEs in the couch‑auth NPM package, providing links to CVE records but offering no further technical, exploit, or patch information.
CVE@CVEnewDisclosure
The statement discloses a host header injection vulnerability in @perfood/couch-auth v0.26.0, enabling attackers to steal reset tokens and perform account takeover.
The Hacker Wire@TheHackerWireDisclosure
This tweet announces a host header injection vulnerability in perfood/couch-auth v0.26.0 that enables attackers to steal reset tokens and take over accounts, with no PoC, exploit code, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A tweet announces CVE-2025-70948 as a Host Header Injection vulnerability in @perfood/couch-auth v0.26.0, providing a link to vulnerability details without evidencing a PoC, exploit code, or patch.