Junglewise Threat Intelligence

CVE-2026-100870: Sylius password-reset link Host header injection

CVE-2026-100870 · Severity: high · CVSS 8.8 · Published 2026-09-27

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius, an open-source e-commerce platform, builds administrator password-reset links using untrusted request headers without validation. An attacker can forge requests with malicious Host headers to redirect password-reset tokens to attacker-controlled domains, compromising administrator accounts and gaining full control of the e-commerce system.

Technical details

The vulnerability exists in password-reset link generation, where the application constructs reset URLs using the HTTP Host header directly without validation. An unauthenticated attacker can request a password reset for a known administrator email address while supplying a forged Host header, causing the reset token to be sent to an attacker-controlled domain. This allows token interception and subsequent account takeover.

Affected products

  • Sylius Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9

Timeline

  • 2026-09-27: disclosed

References

Related threats