- Status Closed
-
Assigned To
cbay - Private
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026
FS#517 - 500 ISE via Host Header @ Injection on /password/lost/ (CVSS 3.3 Low)
## Summary
Injecting @ into the Host header (Host: admin.alwaysdata.com@evil.com) triggers an unhandled HTTP 500 Internal Server Error on /password/lost/. Standard Host values work correctly.
Severity: Low (CVSS 3.3) | CWE-20 (Improper Input Validation)
CVSS: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
## Reproduce
Raw TCP/TLS request:
Host: admin.alwaysdata.com@evil.com GET /password/lost/ HTTP/1.1
Response: HTTP/1.1 500 Internal Server Error
Normal Host: admin.alwaysdata.com returns HTTP 200.
## Evidence
- @-injection in Host header triggers 500 ISE
- Clean Host value returns 200 (no issue)
- No data leakage in error response observed
## Impact
Indicates Host header input reaches internal processing (likely URL building for reset links) without sanitization. Low severity as no data leakage or privilege escalation was demonstrated.
## Remediation
Validate Host header against known-good hostname allowlist at nginx/Django level. Reject requests with malformed Host values (@ symbols, newlines, non-hostname chars) with HTTP 400.
Researcher: adityahadipratama4@gmail.com
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
That's not a vulnerability.
Kind regards,
Cyril