
🔗 Host header poisoning in Perl's Dancer2::Plugin::Auth::Extensible (≤0.713) lets attackers hijack password reset links via _default_email_password_reset & _default_welcome_send. CVSS 9.8. CVE-2026-15689 #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-15689?utm_campaign=x https://t.co/KxMMpi9HLU
Post summary
The tweet announces a host header poisoning vulnerability in Dancer2::Plugin::Auth::Extensible that allows attackers to hijack password reset links, with a CVSS score of 9.8. It provides technical details but no PoC or patch information.


