Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026

FS#517 - 500 ISE via Host Header @ Injection on /password/lost/ (CVSS 3.3 Low)

## Summary

Injecting @ into the Host header (Host: admin.alwaysdata.com@evil.com) triggers an unhandled HTTP 500 Internal Server Error on /password/lost/. Standard Host values work correctly.

Severity: Low (CVSS 3.3) | CWE-20 (Improper Input Validation)
CVSS: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

## Reproduce
Raw TCP/TLS request:

Host: admin.alwaysdata.com@evil.com GET /password/lost/ HTTP/1.1

Response: HTTP/1.1 500 Internal Server Error

Normal Host: admin.alwaysdata.com returns HTTP 200.

## Evidence
- @-injection in Host header triggers 500 ISE
- Clean Host value returns 200 (no issue)
- No data leakage in error response observed

## Impact
Indicates Host header input reaches internal processing (likely URL building for reset links) without sanitization. Low severity as no data leakage or privilege escalation was demonstrated.

## Remediation
Validate Host header against known-good hostname allowlist at nginx/Django level. Reject requests with malformed Host values (@ symbols, newlines, non-hostname chars) with HTTP 400.

Researcher: adityahadipratama4@gmail.com

Closed by  cbay
05.10.2026 07:25
Reason for closing:  Invalid
Admin
cbay commented on 05.10.2026 07:25

Hello,

That's not a vulnerability.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing