CVE-2026-100870

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-27); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-27: 1Mentions · 2026-09-28: 109-2709-28
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew

    CVE-2026-100870 Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allow… https://www.cve.org/CVERecord?id=CVE-2026-100870

    00000497
    58.1K followersView on X
  • ThreatAft@ThreatAft

    🚨 SYLIUS — 4 CVEs, ADMIN TAKEOVER • CVE-2026-100871 (8.8) — JWT firewall bypass • CVE-2026-100870 (8.8) — Host-header reset poisoning → https://threataft.com/articles/sylius-mass-disclosure-cve-2026-100870-100871-100872-100869 #Sylius #CVE #PatchNow #CyberSecurity #ThreatIntel

    0000039
    44 followersView on X

Explore more