CVE-2026-100870: Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning via Host Header
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 1.12.25 - Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 1.13.17 - Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 1.14.20 - Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 2.1.16 - Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 2.2.9
Event History
Frequently Asked Questions
Which deployments are affected?
Sylius releases earlier than 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 are affected. Deployments on the corresponding fixed release or a later release in those version lines are not listed as affected.
What does an attacker need to exploit this issue?
The attacker does not need authentication, but must know an administrator email address and be able to submit a password-reset request with a forged Host header. Exploitation also requires the administrator to use the resulting password-reset flow, because the attack has user-interaction requirements.
What is the likely impact if exploitation succeeds?
An attacker can cause the password-reset link to point to an attacker-controlled domain and intercept a valid reset token. That token can be used to take over an administrator account, with high confidentiality, integrity, and availability impact.
How can I determine whether my instance is exposed?
Check the deployed Sylius version against the fixed versions for its release line. An instance is exposed if it uses an earlier listed version and generates administrator password-reset links from an unvalidated request Host header.