THREAT OPS › Threat News › CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
CVE-2026-15689: Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send
<p>Posted by Timothy Legge on Aug 15</p>========================================================================<br /> CVE-2026-15689 CPAN Security Group<br /> ========================================================================<br /> <br /> CVE ID: CVE-2026-15689<br /> Distribution: Dancer2-Plugin-Auth-Extensible<br /> Versions: thro
Indicators of compromise
- CVE-2026-15689cve
- https://metacpan.org/dist/Dancer2-Plugin-Auth-Extensibleurl
Original source: https://seclists.org/oss-sec/2026/q3/503