← Voltar à pesquisa de CVEs

CVE-2026-42606

AzuraCast

Descrição

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting this header when triggering the forgot-password flow. When the victim clicks the poisoned link, their reset token is exfiltrated to the attacker-s server. The attacker then uses the token on the real instance to reset the victim-s password and destroy their 2FA configuration, achieving full account takeover. This issue has been patched in version 0.23.6.

CVSS 8.1EPSS 0.47600000000000003%Risco 0.84
Ver fonte
Publicação
2026-05-09 20:16:30
Versões afetadas
<0.23.6
Tipo
Installed app
Última alteração
2026-07-24 19:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N