Sceawere

Vulnerability Detail

CVE-2026-100870UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Sylius Host Header Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
19h ago
Vendor
Sylius
Product
Sylius
Attack Type
Weak Password Recovery Mechanism for Forgotten Password
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-27T13:16:38.240Z",
  "pubdate": "2026-09-27T13:16:38.240Z",
  "executiveSummary": "The vulnerability involves an improper trust configuration regarding the HTTP Host header within the Sylius password reset functionality. By failing to validate the Host header against a whitelist of authorized domains, the application generates password reset URLs that point to attacker-controlled infrastructure.\nThis vulnerability is classified as a Host Header Injection flaw, which facilitates critical account takeover attacks. An unauthenticated attacker can target known administrator email addresses, trigger a reset request, and intercept the resulting token via the attacker-specified domain.\nThe issue affects multiple Sylius release branches including versions prior to 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9. Successful exploitation results in the unauthorized takeover of administrative accounts, potentially leading to full compromise of the e-commerce platform.\nThis represents a high-risk security deficiency as it bypasses standard authentication and password recovery protections, leveraging the application's own mail delivery mechanism to exfiltrate valid cryptographic reset tokens.",
  "technicalDetails": "The root cause of this vulnerability lies in the application's reliance on the untrusted 'Host' header provided in the HTTP request to construct absolute URLs for the password reset notification emails. The underlying mechanism utilizes this header to determine the base URL for the reset token link rather than relying on a strictly defined configuration variable or an environment-specific base URL.\nThe exploitation flow begins when an unauthenticated attacker identifies a target administrative email address. The attacker initiates a standard password reset request through the Sylius password recovery form. During the transmission of the POST request to the server, the attacker injects a malicious 'Host' header (e.g., 'Host: attacker-controlled-domain.com').\nThe application processes the request and subsequently triggers an email to the administrative user. Because the application blindly trusts the 'Host' header, the generated link in the email is formatted as 'http://attacker-controlled-domain.com/password-reset/token-value'. When the administrator receives the email and clicks the link, the legitimate reset token is sent directly to the attacker’s server logs via the Referer header or direct request, depending on the attacker's listener setup.\nThe exposure is strictly unauthenticated, requiring no prior system access or session credentials. The vulnerability resides within the application's email generation logic where the URI components are assembled. Because the server uses the attacker-provided host, it essentially facilitates an out-of-band (OOB) data exfiltration vector.\nAffected versions include any Sylius deployment prior to the specified patches: 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9. The vulnerability is network-exposed, as the password reset functionality is typically reachable via the public-facing internet. Post-exploitation, the attacker possesses the cryptographic reset token, allowing them to finalize the password change process and gain full administrative privileges over the affected Sylius instance."
}
CVE-2026-100870: Sylius Host Header Injection Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere