CVE-2026-15689
Received Received - Intake

Password Reset Link Poisoning in Dancer2::Plugin::Auth::Extensible

Vulnerability report for CVE-2026-15689, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: CPANSec

Description

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host under behind_proxy (obtained from Dancer2's request->base function). A POST to /login carrying submit_reset and a username needs no authentication: it stores a fresh reset code against that account and mails the account holder a link to a host of the sender's choosing. The welcome mail takes the same path when the application calls create_user with email_welcome set. Through 0.711 the handlers read `request->uri_base` and `request->base` directly; Versions 0.712 and later provide an uri_base configuration key that defaults to the untrusted `request->uri_base` when unset. The default configuration with reset_password_handler enabled and the default message text, a recipient who follows the link hands a working reset code to the sender's host, which is enough to take over the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
perldancer dancer2_plugin_auth_extensible to 0.713 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-640 The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl. It allows password reset link poisoning via the request Host header or X-Forwarded-Host header. Attackers can manipulate reset links to point to their own servers, enabling account takeover.

Detection Guidance

Check if Dancer2::Plugin::Auth::Extensible versions through 0.713 are installed. Inspect email templates for reset links using the Host header or X-Forwarded-Host. Review server logs for suspicious POST requests to /login with submit_reset and a username.

Impact Analysis

If you use Dancer2::Plugin::Auth::Extensible with default settings, attackers can intercept password reset links. By tricking users into clicking poisoned links, they gain access to accounts without needing the original password. This can lead to unauthorized access and data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using affected software may face compliance violations and potential fines.

Mitigation Strategies

Upgrade to a version of Dancer2::Plugin::Auth::Extensible beyond 0.713. Disable reset_password_handler if not needed. Configure uri_base to a trusted value. Validate and sanitize Host headers and X-Forwarded-Host values in reset links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15689. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart