Urgent.News

What's breaking now, across thousands of outlets.

Tech

The Password Reset Email Was Real. The Destination Wasn't.

The application sends the password-reset email. Its own template. Its own delivery system. The link carries a genuine reset token. But the destination belongs to someone else. That is the unsettling part of password-reset poisoning: the application can assemble and deliver the dangerous message itself. The check was there. It never got its turn. Coolify's advisory describes a chain involving…

The password reset email is genuine, but its destination is not as intended. The application constructs and delivers the dangerous password reset link itself, rather than relying on the recipient's email client to complete the process. The vulnerability stems from a bug in handling forwarded headers and a cache validation issue.

By manipulating the "x-forwarded-host" header, an attacker can trick the application into sending the reset link to a different domain than the one the user initially intended. For example, if a recipient clicks the forged link from "collector.example", the reset token will be sent to that domain instead of the expected "app.example" domain.

The fix involves using a fixed destination server specified in application configuration, rather than relying on potentially untrusted headers. The repaired function builds the link using a hard-coded origin server, effectively removing any possibility of the reset link being sent to an unintended destination.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

LINQ Aggregate Operators: Beyond Sum and Count

LINQ Aggregate Operators: Beyond Sum and Count Everyone knows Count() and Sum() . But LINQ's aggregate family goes deeper — and the general-purpose Aggregate() operator can implement any of them, plus…

Flash Loan Attack Vector Analysis: Portal

Flash Loan Attack Vector Analysis: Portal Target Protocol : Portal (TVL: $1805.6M) Flash Loan Attack Vector Analysis – Portal Protocol: Portal (TVL ≈ $1.805 B across Ethereum L1 & L2) Prepared by…

More from Tuesday 29 September →