Junglewise Threat Intelligence

CVE-2026-35507: milesmcc Shynet Host header injection in password reset flow

CVE-2026-35507 · Severity: medium · CVSS 6.4 · Published 2026-04-03

Executive brief

Shynet, an open-source web analytics platform, contains a security flaw in its password reset system. An attacker can trick the system into sending a legitimate password reset email that contains a link pointing to a malicious website. If a user clicks this link, the attacker can capture their secret reset token and take over their account.

Technical details

A Host header injection vulnerability exists in Shynet's password reset flow due to a default configuration of ALLOWED_HOSTS = "*" in the underlying Django framework. The application uses django-allauth, which generates absolute URLs for password reset emails based on the Host header provided in the HTTP request. An unauthenticated remote attacker can submit a password reset request with a spoofed Host header, causing the system to send an email to the victim containing a reset link pointing to an attacker-controlled domain. If the victim clicks the link or an automated email scanner previews it, the valid reset token is leaked to the attacker. This has been fixed in version 0.14.0 by restricting the default ALLOWED_HOSTS.

Affected products

  • milesmcc Shynet < 0.14.0

Timeline

  • 2026-03-15: patched: Fix merged in pull request #345 and released in v0.14.0
  • 2026-04-03: disclosed: CVE published to NVD

References

Related threats