PatchSiren cyber security CVE debrief
CVE-2026-42606 AzuraCast CVE debrief
CVE-2026-42606 is a high-severity vulnerability in AzuraCast’s ApplyXForwarded middleware that trusted the client-supplied X-Forwarded-Host header without a trusted-proxy allowlist. An unauthenticated attacker could influence the host used in a forgot-password email, poison the reset URL, and cause the reset token to be sent to an attacker-controlled destination when the victim clicked the link. With the token, the attacker could then complete password reset on the real instance and take over the account. The issue is fixed in AzuraCast 0.23.6.
- Vendor
- AzuraCast
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
AzuraCast operators, administrators, and security teams should prioritize this if their deployment exposes password reset functionality to users and sits behind a reverse proxy or any network path where forwarded headers may be accepted.
Technical summary
The vulnerable middleware accepted X-Forwarded-Host from the client without verifying that the request came through a trusted proxy. During the forgotten-password flow, that host value could be reflected into the generated reset URL. Because the reset link could be poisoned before it reached the victim, the victim’s click could disclose the reset token to an attacker-controlled server. The attack requires no authentication, but it does require user interaction. The supplied metadata maps the issue to CWE-640 and CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N.
Defensive priority
High
Recommended defensive actions
- Upgrade AzuraCast to version 0.23.6 or later.
- Review reverse-proxy and application handling of forwarded headers; only trust X-Forwarded-Host when the request is known to come from an approved proxy.
- Validate that password reset links are generated with the expected canonical host and that untrusted host headers cannot alter them.
- Invalidate and reissue any exposed password-reset tokens if abuse is suspected.
- Encourage affected users to reset passwords and confirm 2FA settings after remediation if there is any indication of compromise.
Evidence notes
The debrief is based on the CVE description and the linked GitHub Security Advisory, commit, and release record. The official NVD entry lists the issue as received on 2026-05-09 and includes the CVSS vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N plus CWE-640. No additional exploit mechanics beyond the supplied sources are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AzuraCast/AzuraCast/commit/7c622a18b451533de317e53862b1f84acf4efd85
-
Source reference
Unverified legacy reference
URL: https://github.com/AzuraCast/AzuraCast/releases/tag/0.23.6
-
Source reference
Unverified legacy reference
URL: https://github.com/AzuraCast/AzuraCast/security/advisories/GHSA-gv7r-3mr9-h5x8
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.