CVE-2026-42606

high
Published 2026-05-04 · Modified 2026-05-13
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS v2
VIR risk
8.8

Description

AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-gv7r-3mr9-h5x8

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/AzuraCast/AzuraCast/commit/7c622a18b451533de317e53862b1f84acf4efd85

Package impact

EcosystemPackageVulnerableFixed
php Packagistazuracast/azuracast<=0.23.5
php Packagistazuracast/azuracast<0.23.60.23.6
php COMPOSERazuracast/azuracast<= 0.23.50.23.6

Application impact

VendorProductVersionsFixed
azuracastazuracast{"endExcluding":"0.23.6"}0.23.6

References

CWEs

CWE-640

Verify integrity in audit chain (admin only). AS-IS.