THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes fr

[NVD] CVE-2026-15689 — Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes fr

mednvdPublished 2026-08-15

CVE-2026-15689 CVSS: None Published: 2026-08-15T14:17:06.480

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send.

Both default emails emit a link of the form `$base/login/$code`, whose authority comes from the request Host header, or from X-Forwarded-Host unde

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15689

Same event, other sources