← Zurück zur CVE-Suche

CVE-2026-42606

AzuraCast

Beschreibung

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting this header when triggering the forgot-password flow. When the victim clicks the poisoned link, their reset token is exfiltrated to the attacker-s server. The attacker then uses the token on the real instance to reset the victim-s password and destroy their 2FA configuration, achieving full account takeover. This issue has been patched in version 0.23.6.

CVSS 8.1EPSS 0.47600000000000003%Risiko 0.84
Quelle öffnen
Veröffentlicht
2026-05-09 20:16:30
Betroffene Versionen
<0.23.6
Typ
Installed app
Zuletzt geändert
2026-07-24 19:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N