CVE-2025-70948
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2026
Last modified:
06/03/2026
Description
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.
Impact
Base Score 3.x
9.30
Severity 3.x
CRITICAL



