{
  "id": 10775523,
  "title": "The Password Reset Email Was Real. The Destination Wasn't.",
  "url": "https://urgent.news/2026/09/29/the-password-reset-email-was-real-the-destination-wasnt",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T20:34:44.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/ookeolioli222/the-password-reset-email-was-real-the-destination-wasnt-568a"
  },
  "original_language": "en",
  "account": "The password reset email is genuine, but its destination is not as intended. The application constructs and delivers the dangerous password reset link itself, rather than relying on the recipient's email client to complete the process. The vulnerability stems from a bug in handling forwarded headers and a cache validation issue.\n\nBy manipulating the \"x-forwarded-host\" header, an attacker can trick the application into sending the reset link to a different domain than the one the user initially intended. For example, if a recipient clicks the forged link from \"collector.example\", the reset token will be sent to that domain instead of the expected \"app.example\" domain.\n\nThe fix involves using a fixed destination server specified in application configuration, rather than relying on potentially untrusted headers. The repaired function builds the link using a hard-coded origin server, effectively removing any possibility of the reset link being sent to an unintended destination.",
  "summary": "The application sends the password-reset email. Its own template. Its own delivery system. The link carries a genuine reset token. But the destination belongs to someone else. That is the unsettling part of password-reset poisoning: the application can assemble and deliver the dangerous message itself. The check was there. It never got its turn. Coolify's advisory describes a chain involving…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}