Weak Password Recovery Mechanism for Forgotten Password Affecting azuracast/azuracast package, versions <0.23.6


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.48% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-AZURACASTAZURACAST-16419414
  • published5 May 2026
  • disclosed4 May 2026
  • creditoffset

Introduced: 4 May 2026

CVE-2026-42606  (opens in a new tab)
CWE-640  (opens in a new tab)

How to fix?

Upgrade azuracast/azuracast to version 0.23.6 or higher.

Overview

Affected versions of this package are vulnerable to Weak Password Recovery Mechanism for Forgotten Password via the ApplyXForwarded process. An attacker can gain unauthorized access to user accounts and bypass two-factor authentication by injecting a malicious X-Forwarded-Host header during the password reset flow, causing password reset emails to contain attacker-controlled URLs. When victims click these links, their reset tokens are exfiltrated, allowing the attacker to reset passwords and disable 2FA.

CVSS Base Scores

version 4.0
version 3.1