HIGH8.1npm
GHSA-fqh6-6h6c-366m· CVE-2023-39655CouchAuth host header injection vulnerability leaks the password reset token
Modified: 1/3/2024
package
pkg:npm/%40perfood/couch-auth
CouchAuth host header injection vulnerability leaks the password reset token
Modified: 1/3/2024
@perfood/couch-auth may expose session tokens, passwords
Modified: 11/20/2025
@perfood/couch-auth has an Observable Timing Discrepancy
Modified: 3/6/2026
@perfood/couch-auth has a host header injection vulnerability
Modified: 3/6/2026
CouchAuth has a Server-Side Template Injection vulnerability in its email functionality
Modified: 12/18/2025