CRITICAL
ABEVERLEY
CVE published 2026-08-15
CVE-2026-15689
The CVE record for CVE-2026-15689 was published on 2026-08-15T14:17:06.480Z and has not been modified since then. The NVD entry is currently Deferred. Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. The vulnerability arises from the use of untrusted input from the r [truncated]