CVE-2026-81179

Source
https://cve.org/CVERecord?id=CVE-2026-81179
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81179.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81179
Aliases
  • GHSA-9x2r-5pff-8w6c
Published
2026-09-18T17:45:58Z
Modified
2026-09-20T11:47:27Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
Summary
SysReptor: Host header injection might allow account takeover
Details

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-807"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81179.json"
}
References

Affected packages

Git / github.com/syslifters/sysreptor

Affected ranges

Type
GIT
Repo
https://github.com/syslifters/sysreptor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2026.58"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.101
0.102
0.110
0.83
0.87
0.89
0.95
0.96
2023.*
2023.114
2023.119
2023.122
2023.128
2023.136
2023.142
2023.145
2024.*
2024.1
2024.10
2024.13
2024.16
2024.19
2024.20
2024.28
2024.29
2024.3
2024.30
2024.40
2024.43
2024.49
2024.55
2024.57
2024.58
2024.60
2024.61
2024.63
2024.68
2024.69
2024.70
2024.74
2024.79
2024.8
2024.81
2024.91
2024.96
2025.*
2025.102
2025.104
2025.108
2025.110
2025.12
2025.20
2025.25
2025.29
2025.37
2025.4
2025.43
2025.50
2025.56
2025.64
2025.69
2025.74
2025.80
2025.81
2025.83
2025.90
2025.94
2025.96
2026.*
2026.1
2026.12
2026.18
2026.21
2026.25
2026.27
2026.29
2026.36
2026.4
2026.42
2026.50
2026.55

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81179.json"