{"id":"CVE-2026-81179","summary":"SysReptor: Host header injection might allow account takeover","details":"SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.","aliases":["GHSA-9x2r-5pff-8w6c"],"modified":"2026-09-20T11:47:27.132631296Z","published":"2026-09-18T17:45:58.249Z","database_specific":{"cwe_ids":["CWE-807"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81179.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/Syslifters/sysreptor/releases/tag/2026.58"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81179.json"},{"type":"ADVISORY","url":"https://github.com/Syslifters/sysreptor/security/advisories/GHSA-9x2r-5pff-8w6c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81179"},{"type":"FIX","url":"https://github.com/Syslifters/sysreptor/commit/7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/syslifters/sysreptor","events":[{"introduced":"0"},{"fixed":"7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea"},{"fixed":"1c3c8e8a7070f7ef575c3b8365238d93e9652cc2"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"2026.58"}]}}],"versions":["2026.55","2026.50","2026.42","2026.36","2026.29","2026.27","2026.25","2026.21","2026.18","2026.12","2026.4","2026.1","2025.110","2025.108","2025.104","2025.102","2025.96","2025.94","2025.90","2025.83","2025.81","2025.80","2025.74","2025.69","2025.64","2025.56","2025.50","2025.43","2025.37","2025.29","2025.25","2025.20","2025.12","2025.4","2024.96","2024.91","2024.81","2024.79","2024.74","2024.70","2024.69","2024.68","2024.63","2024.61","2024.60","2024.58","2024.57","2024.55","2024.49","2024.43","2024.40","2024.30","2024.29","2024.28","2024.20","2024.19","2024.16","2024.13","2024.10","2024.8","2024.3","2024.1","2023.145","2023.142","2023.136","2023.128","2023.122","2023.119","2023.114","0.110","0.102","0.101","0.96","0.95","0.89","0.87","0.83"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81179.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}