๐Ÿ” CVE Alert

CVE-2026-42606

HIGH 8.1

AzuraCast: Password Reset Poisoning via Untrusted X-Forwarded-Host Header Leads to Account Takeover and 2FA Bypass

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
12th

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated attacker can poison the password reset URL sent to any user by injecting this header when triggering the forgot-password flow. When the victim clicks the poisoned link, their reset token is exfiltrated to the attacker's server. The attacker then uses the token on the real instance to reset the victim's password and destroy their 2FA configuration, achieving full account takeover. This issue has been patched in version 0.23.6.

CWE CWE-640
Vendor azuracast
Product azuracast
Published May 9, 2026
Last Updated May 12, 2026
Stay Ahead of the Next One

Get instant alerts for azuracast azuracast

Be the first to know when new high vulnerabilities affecting azuracast azuracast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

AzuraCast / AzuraCast
< 0.23.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-gv7r-3mr9-h5x8 github.com: https://github.com/AzuraCast/AzuraCast/commit/7c622a18b451533de317e53862b1f84acf4efd85 github.com: https://github.com/AzuraCast/AzuraCast/releases/tag/0.23.6