📦 Couchauth

by Perfood

🔍 What is Couchauth?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-39655

CRITICAL CVSS 9.6 Jan 3, 2024

This host header injection vulnerability in @perfood/couch-auth allows attackers to send password reset links that redirect to attacker-controlled servers, leaking reset tokens. Attackers can then res...

CVE-2025-60794

MEDIUM CVSS 6.5 Nov 20, 2025

CVE-2025-60794 exposes sensitive authentication data (session tokens and passwords) in couch-auth 0.21.2 due to improper memory clearing. This allows attackers with memory access capabilities to extra...