VYPR

Dancer2::Plugin::Auth::Extensible

by Perl Foundation

CVEs (1)

  • CVE-2026-15689CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a link of the form `$base/login/$code`, whose authority comes…