rpm package
opensuse/perl-Dancer2-Plugin-Auth-Extensible&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/perl-Dancer2-Plugin-Auth-Extensible&distro=openSUSE%20Tumbleweed
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-15689 | Cri | 9.8 | < 0.713.0-1.1 | 0.713.0-1.1 | Aug 15, 2026 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes fr |
- affected < 0.713.0-1.1fixed 0.713.0-1.1
Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes fr