CVE-2026-35507
MEDIUM
6,4
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: low
Integrity: high
Availability: low
Description
AI Translation Available
Shynet before 0.14.0 allows Host header injection in the password reset flow.
348
Use of Less Trusted Source
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://github.com/milesmcc/shynet/pull/345
https://github.com/milesmcc/shynet/releases/tag/v0.14.0