CVE-2026-15689Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set. Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset. The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-15); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-15: 2Mentions · 2026-08-18: 1Technical Details · 2026-08-15: 2Technical Details · 2026-08-18: 108-1508-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-152
Disclosure2
2026-08-181
Disclosure1
Full discourse3 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🔗 Host header poisoning in Perl's Dancer2::Plugin::Auth::Extensible (≤0.713) lets attackers hijack password reset links via _default_email_password_reset & _default_welcome_send. CVSS 9.8. CVE-2026-15689 #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-15689?utm_campaign=x https://t.co/KxMMpi9HLU

    Post summary

    The tweet announces a host header poisoning vulnerability in Dancer2::Plugin::Auth::Extensible that allows attackers to hijack password reset links, with a CVSS score of 9.8. It provides technical details but no PoC or patch information.

    0001076
    879 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15689 Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and… https://www.cve.org/CVERecord?id=CVE-2026-15689 ----- Traducción: CVE-2026-15689 Dan… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-15689 affecting Dancer2::Plugin::Auth::Extensible, detailing a password reset link poisoning issue via the Host header, but provides no PoC, exploit, active exploitation claim, or patch information.

    0000031
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15689 Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and… https://www.cve.org/CVERecord?id=CVE-2026-15689

    Post summary

    The text discloses a Host header-based password reset link poisoning vulnerability in Dancer2::Plugin::Auth::Extensible versions up to 0.713.

    000001.1K
    57.9K followersView on X

Explore more