CVE-2025-70948
EUVD-2025-20832705.03.2026, 21:16
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.